skills/johnlindquist/claude/github/Gen Agent Trust Hub

github

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes content from GitHub issues, which are external and user-controlled.
  • Ingestion points: In VIEW_ISSUE.md and LIST_ISSUES.md, the agent is instructed to fetch issue details including titles, bodies, and comments.
  • Boundary markers: No specific boundary markers or instructions are provided to the agent to distinguish between its instructions and the data fetched from GitHub.
  • Capability inventory: The skill possesses the capability to write to the repository (create/edit/comment/close/assign) and execute gh CLI commands.
  • Sanitization: There is no evidence of sanitization or safety-filtering for the content retrieved from external sources.
  • [DYNAMIC_EXECUTION]: The skill employs dynamic script generation and execution techniques at runtime.
  • Evidence: CREATE_ISSUE.md includes a line that executes node to programmatically determine the temporary directory and a timestamp for naming files.
  • Evidence: UPDATE_ISSUE.md and ASSIGN_ISSUE.md provide instructions to use shell heredocs (cat << 'EOF') to create temporary markdown files on the fly.
  • [COMMAND_EXECUTION]: The skill operates by executing shell commands via the gh CLI, using arguments that may be derived from potentially untrusted external issue data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:25 PM
Security Audit — agent-trust-hub — github