Triage eligible fetch

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script fetch.py invokes the gh (GitHub CLI) tool to perform GraphQL queries. It uses subprocess.run with arguments passed as a list, which is a secure practice that prevents shell injection vulnerabilities. The execution is limited to the system's installed GitHub client for its primary function.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content from GitHub issues and pull requests to calculate triage priority.
  • Ingestion points: Untrusted data enters the skill via GitHub API responses in fetch.py (specifically issue and PR titles, bodies, and comments fetched in paginate_nodes).
  • Boundary markers: The script does not use explicit boundary markers or delimiters when handling the text content of issues, as it is primarily used for ranking logic rather than re-interpolation into further prompts within the script itself.
  • Capability inventory: The skill has the capability to execute the gh binary via subprocess.run for data retrieval across multiple scripts (e.g., fetching comments, commits, and reviews).
  • Sanitization: The script uses regular expressions (like STAMP_RE and CLOSING_LIST_RE) to strictly filter and extract specific metadata (triage stamps and closing keywords) from the untrusted text rather than treating the text as executable instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:31 PM
Security Audit — agent-trust-hub — Triage eligible fetch