chalk
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it is designed to ingest and process data from external GitHub issues and comments.
- Ingestion points: The
Activation: chalk #Nsection inSKILL.mdrequires the agent to read the issue body, recent comments, and the issue neighborhood (parent/child relationships) before beginning a session. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when reading content from GitHub, which could allow instructions embedded in issue comments to influence agent behavior.
- Capability inventory: The skill has significant write capabilities via the
chalk:githubsub-agent, including creating issues, posting comments, and mutating issue relationships through GraphQL mutations. - Sanitization: There are no requirements for sanitizing or validating the data retrieved from GitHub before it is internalized by the agent or included in drafted prose.
Audit Metadata