is
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from GitHub issues, comments, and pull requests (ingestion points in SKILL.md). It proactively mitigates this risk by providing boundary markers in the instructions, such as 'Do not trust analysis in the issue' and 'Verify the behavior independently'. The agent's capabilities include file reading and GitHub CLI usage. The skill uses prompt-based sanitization by forcing the agent to derive analysis from execution paths rather than issue content.\n- [COMMAND_EXECUTION]: The skill utilizes the GitHub CLI (gh) to update issue labels. This interaction is limited to a single specific task and is aligned with the skill's intended functionality.
Audit Metadata