create-issue-to-rebase-wip
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local git commit history, which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: The skill reads back prior git commits to extract summaries (SKILL.md).
- Boundary markers: No explicit delimiters or instructions are provided to the agent to treat the commit content as data rather than instructions.
- Capability inventory: The agent uses the
ghCLI for GitHub issue creation, executesgit rebasefor local file system modification, and invokes thedraft-commit-messageskill. - Sanitization: There is no evidence of sanitization, escaping, or validation of the commit message content before it is processed or used to generate new commands.
Audit Metadata