github-issue

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub issues and projects, which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: The agent reads external data using commands like gh issue view, gh issue list, and gh project item-list as defined in references/gh-commands.md.
  • Boundary markers: The skill includes a HARD-GATE instruction in SKILL.md that explicitly requires direct user authorization for state-changing actions, serving as a manual security boundary.
  • Capability inventory: The skill possesses capabilities to create, edit, and close issues, as well as modify project boards using gh issue commands and gh api graphql.
  • Sanitization: The instructions do not specify any sanitization or validation steps for the data retrieved from GitHub before it is analyzed by the agent.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the GitHub CLI tool.
  • Evidence: references/gh-commands.md provides a reference of gh CLI commands and GraphQL queries that the agent uses to interact with repository data and project boards.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:24 AM
Security Audit — agent-trust-hub — github-issue