skills/lucas-ataides/skills/to-issues/Gen Agent Trust Hub

to-issues

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill uses a local script scripts/to-issues.py to interface with the GitHub CLI (gh). The script executes commands using subprocess.run() with a list of arguments, which is a secure practice to prevent shell injection. Evidence: subprocess.run(cmd) in scripts/to-issues.py.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted source text to generate issues, creating a potential surface for indirect prompt injection. However, the risk is mitigated by a multi-step process: (1) Ingestion points: Source text collection in SKILL.md Step 1. (2) Boundary markers: The agent is instructed to draft issues into a rigid JSON spec. (3) Capability inventory: The skill can only create issues via the gh tool. (4) Sanitization: The to-issues.py script performs deterministic validation, and Step 7 in SKILL.md requires explicit human approval of the final command before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 07:15 PM
Security Audit — agent-trust-hub — to-issues