kf-g-command-do-issue-planning

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes GitHub issues, which are external, untrusted data sources. Malicious instructions embedded within an issue could potentially influence the agent during the planning or implementation phases.
  • Ingestion points: Processes external data by referring to GitHub issues (SKILL.md).
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat issue content as untrusted data.
  • Capability inventory: The skill allows for code implementation, execution of verification commands (tests, lint), and network operations like creating Pull Requests and posting comments (SKILL.md).
  • Sanitization: There is no mention of sanitization or validation for the content retrieved from GitHub issues.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 06:01 AM
Security Audit — agent-trust-hub — kf-g-command-do-issue-planning