github-project-manager

Warn

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing an unverified third-party GitHub CLI extension (yahsan2/gh-sub-issue) to enable native sub-issue support.
  • [PROMPT_INJECTION]: The skill exhibits an Indirect Prompt Injection surface (Category 8). * Ingestion points: The agent reads content from CLAUDE.md, AGENTS.md, and existing GitHub issues (titles and bodies) to generate work items. * Boundary markers: None. Content from external sources is interpolated into issue bodies without delimiters or instructions to ignore embedded commands. * Capability inventory: Can create or modify GitHub issues, labels, and project board items using the gh CLI. * Sanitization: No explicit sanitization or validation is applied to content fetched from repository files or issue metadata.
  • [COMMAND_EXECUTION]: The skill makes extensive use of the GitHub CLI (gh) to perform repository discovery, issue tracking, and project board automation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 13, 2026, 08:45 AM
Security Audit — agent-trust-hub — github-project-manager