summarize-lanes
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub that could potentially contain malicious or misleading instructions.
- Ingestion points: Data is ingested from GitHub issue bodies, issue comments, and Pull Request bodies via
gh pr viewand GitHub API calls (documented indetailed-summary.md). - Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present in the processing logic.
- Capability inventory: The skill utilizes the GitHub CLI (
gh) for various read operations across the repository. - Sanitization: There is no evidence of sanitization, validation, or escaping of the content retrieved from external GitHub sources before it is formatted into the final summary.
- [COMMAND_EXECUTION]: The skill executes shell commands using the GitHub CLI to retrieve repository information.
- Evidence: The skill uses commands such as
gh issue list,gh pr list,gh pr view, andgh apito gather the necessary data for generating lane summaries. These commands are consistent with the skill's stated purpose of providing project status updates.
Audit Metadata