split-issue-into-subissues
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from issue titles, bodies, and linked documentation (Ingestion: SKILL.md Step 1). While managed section markers are used for output, specific input boundaries are not defined (Boundaries: SKILL.md Step 7). The agent can create/modify issues and read local code (Capabilities: SKILL.md Steps 6, 8). Sanitization is absent, but the mandatory user approval gate (Step 5) provides a robust control against autonomous execution of malicious instructions embedded in input data.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill follows security best practices by explicitly instructing the agent not to expose authentication tokens or credentials in its output (Tool guidance).
Audit Metadata