skills/juxt/claude-plugins/chalk/Gen Agent Trust Hub

chalk

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it is designed to ingest and process data from external GitHub issues and comments.
  • Ingestion points: The Activation: chalk #N section in SKILL.md requires the agent to read the issue body, recent comments, and the issue neighborhood (parent/child relationships) before beginning a session.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when reading content from GitHub, which could allow instructions embedded in issue comments to influence agent behavior.
  • Capability inventory: The skill has significant write capabilities via the chalk:github sub-agent, including creating issues, posting comments, and mutating issue relationships through GraphQL mutations.
  • Sanitization: There are no requirements for sanitizing or validating the data retrieved from GitHub before it is internalized by the agent or included in drafted prose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 07:24 PM