analyze-issue
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted content from external GitHub issues, creating a vulnerability to indirect prompt injection.
- Ingestion points: External GitHub issue data (title, body, labels, etc.) fetched based on the provided issue number.
- Boundary markers: Absent. The instructions do not specify any delimiters or safety warnings to ensure the agent ignores instructions found within the processed issue content.
- Capability inventory: The agent is authorized to read local files, execute data-fetching commands defined in the project, and write technical specification files to the disk.
- Sanitization: No sanitization or filtering of the external issue data is performed before processing.
- [COMMAND_EXECUTION]: The skill directs the agent to follow instructions located in
.claude/commands/load-issues.mdto fetch issue details. This process likely involves executing shell commands or CLI tools (such asghorcurl) that utilize the user-provided$ARGUMENTSas input. - [PROMPT_INJECTION]: The skill interpolates the user-supplied
$ARGUMENTSdirectly into its instructions (e.g.,Please analyze GitHub issue #$ARGUMENTS). A user could provide a malicious payload as the issue number to attempt to override agent instructions or extract system prompts.
Audit Metadata