research
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources, specifically GitHub repositories and issue descriptions, and processes them using an AI model via the gemini CLI.
- Ingestion points: The skill uses
gh search reposandgh search issuesinSKILL.mdto collect external data. - Boundary markers: Absent. The external data is interpolated directly into natural language prompt strings.
- Capability inventory: The skill executes shell commands via the GitHub and Gemini CLI tools.
- Sanitization: Absent. Since GitHub issues can contain user-generated content, an attacker could craft an issue with malicious instructions intended to influence the AI's research synthesis when the skill processes that data.
- [COMMAND_EXECUTION]: Several bash patterns in the skill interpolate variables directly into shell command arguments without explicit sanitization.
- Evidence: Patterns such as
gh search repos "$LIB"andgemini ... "Explain this error: $ERROR"inSKILL.mdrely on the shell to handle the variables. If these variables contain shell metacharacters like semicolons, backticks, or pipes, it could result in unintended command execution if the agent does not strictly validate the input.
Audit Metadata