issue
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted content from existing GitHub issues and search results to generate new issue descriptions or updates. This ingestion of external data without explicit boundary markers or sanitization creates a surface where malicious instructions embedded in issue comments or bodies could influence the agent's output.
- Ingestion points: Data enters the agent's context through GitHub issue search results and existing issue bodies retrieved by the 'github agent' (SKILL.md).
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings for content fetched from GitHub.
- Capability inventory: The skill possesses the capability to create and update GitHub issues, including defining their titles and bodies, and wiring up relationships like sub-issues and dependencies (SKILL.md).
- Sanitization: There are no instructions provided for escaping, validating, or filtering the external content before it is interpolated into the generated issue prose.
Audit Metadata