github
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes content from GitHub issues, which are external and user-controlled.
- Ingestion points: In
VIEW_ISSUE.mdandLIST_ISSUES.md, the agent is instructed to fetch issue details including titles, bodies, and comments. - Boundary markers: No specific boundary markers or instructions are provided to the agent to distinguish between its instructions and the data fetched from GitHub.
- Capability inventory: The skill possesses the capability to write to the repository (create/edit/comment/close/assign) and execute
ghCLI commands. - Sanitization: There is no evidence of sanitization or safety-filtering for the content retrieved from external sources.
- [DYNAMIC_EXECUTION]: The skill employs dynamic script generation and execution techniques at runtime.
- Evidence:
CREATE_ISSUE.mdincludes a line that executesnodeto programmatically determine the temporary directory and a timestamp for naming files. - Evidence:
UPDATE_ISSUE.mdandASSIGN_ISSUE.mdprovide instructions to use shell heredocs (cat << 'EOF') to create temporary markdown files on the fly. - [COMMAND_EXECUTION]: The skill operates by executing shell commands via the
ghCLI, using arguments that may be derived from potentially untrusted external issue data.
Audit Metadata