lifeguard-in-lanes
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub issue bodies and comments to monitor workflow status, which could be used to influence the agent's reporting or nudge behavior.
- Ingestion points: Reads issue body (lanes, handoffs, merge order) and all comments (CHECK-IN, HANDOFF, STUCK, DONE, LIFEGUARD) via the GitHub API.
- Boundary markers: None present; the skill lacks explicit delimiters or instructions to ignore malicious content within the comments.
- Capability inventory: The skill can execute GitHub CLI commands (
gh pr view,gh api), send messages to other agent sessions (SendMessage), and send push notifications to the human user (PushNotification). - Sanitization: There is no mention of sanitization or validation for the content retrieved from issue comments before it is used to determine the lane state.
- [COMMAND_EXECUTION]: The skill executes
gh(GitHub CLI) commands and API calls using parameters such as SHAs and branch names extracted directly from external issue comments. This represents a potential command injection surface if the underlying platform does not properly escape these parameters before shell execution.
Audit Metadata