github-project-manager

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to prompt the user to install a third-party GitHub CLI extension from an unverified community source.
  • Evidence: The workflow includes the command gh extension install yahsan2/gh-sub-issue in SKILL.md. This extension executes code with the privileges of the authenticated GitHub user.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local repository files and interpolates the content into GitHub issues without sanitization, creating a surface for indirect prompt injection if the repository contains malicious instructions.
  • Ingestion points: The skill reads CLAUDE.md, AGENTS.md, and CONTRIBUTING.md to extract conventions and coding standards.
  • Boundary markers: No explicit delimiters or instructions are provided to the LLM to ignore potentially malicious embedded content within these files.
  • Capability inventory: The skill uses gh issue create, gh issue edit, and gh project item-edit to write data back to GitHub.
  • Sanitization: There is no evidence of validation or filtering for the content extracted from the repository files before it is included in the generated issue bodies.
  • [COMMAND_EXECUTION]: The skill performs extensive shell command execution using the GitHub CLI (gh) and jq to manage repository metadata and project boards.
  • Evidence: Numerous bash code blocks are defined for operations such as listing collaborators, creating labels, and editing project items based on dynamically discovered field IDs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 05:08 PM
Security Audit — agent-trust-hub — github-project-manager