to-issues
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill uses a local script
scripts/to-issues.pyto interface with the GitHub CLI (gh). The script executes commands usingsubprocess.run()with a list of arguments, which is a secure practice to prevent shell injection. Evidence:subprocess.run(cmd)inscripts/to-issues.py. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted source text to generate issues, creating a potential surface for indirect prompt injection. However, the risk is mitigated by a multi-step process: (1) Ingestion points: Source text collection in
SKILL.mdStep 1. (2) Boundary markers: The agent is instructed to draft issues into a rigid JSON spec. (3) Capability inventory: The skill can only create issues via theghtool. (4) Sanitization: Theto-issues.pyscript performs deterministic validation, and Step 7 inSKILL.mdrequires explicit human approval of the final command before execution.
Audit Metadata