github-project-manager
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to prompt the user to install a third-party GitHub CLI extension from an unverified community source.
- Evidence: The workflow includes the command
gh extension install yahsan2/gh-sub-issueinSKILL.md. This extension executes code with the privileges of the authenticated GitHub user. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local repository files and interpolates the content into GitHub issues without sanitization, creating a surface for indirect prompt injection if the repository contains malicious instructions.
- Ingestion points: The skill reads
CLAUDE.md,AGENTS.md, andCONTRIBUTING.mdto extract conventions and coding standards. - Boundary markers: No explicit delimiters or instructions are provided to the LLM to ignore potentially malicious embedded content within these files.
- Capability inventory: The skill uses
gh issue create,gh issue edit, andgh project item-editto write data back to GitHub. - Sanitization: There is no evidence of validation or filtering for the content extracted from the repository files before it is included in the generated issue bodies.
- [COMMAND_EXECUTION]: The skill performs extensive shell command execution using the GitHub CLI (
gh) andjqto manage repository metadata and project boards. - Evidence: Numerous bash code blocks are defined for operations such as listing collaborators, creating labels, and editing project items based on dynamically discovered field IDs.
Audit Metadata