lifeguard-in-lanes

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub issue bodies and comments to monitor workflow status, which could be used to influence the agent's reporting or nudge behavior.
  • Ingestion points: Reads issue body (lanes, handoffs, merge order) and all comments (CHECK-IN, HANDOFF, STUCK, DONE, LIFEGUARD) via the GitHub API.
  • Boundary markers: None present; the skill lacks explicit delimiters or instructions to ignore malicious content within the comments.
  • Capability inventory: The skill can execute GitHub CLI commands (gh pr view, gh api), send messages to other agent sessions (SendMessage), and send push notifications to the human user (PushNotification).
  • Sanitization: There is no mention of sanitization or validation for the content retrieved from issue comments before it is used to determine the lane state.
  • [COMMAND_EXECUTION]: The skill executes gh (GitHub CLI) commands and API calls using parameters such as SHAs and branch names extracted directly from external issue comments. This represents a potential command injection surface if the underlying platform does not properly escape these parameters before shell execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 12:38 PM
Security Audit — agent-trust-hub — lifeguard-in-lanes