load-issues
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the native system
ghCLI tool via subprocess execution to retrieve issue details (gh issue list,gh issue view). It also invokes shell utilities such asmkdir -pto initialize target directories.\n- [INDIRECT_PROMPT_INJECTION]: The skill represents an indirect prompt injection surface because it reads external, untrusted content (GitHub issue titles, bodies, and author metadata) and dynamically formats it into local markdown files.\n - Ingestion points: External issue data returned from the
gh issue viewjson schema payload is embedded dynamically into file structures.\n - Boundary markers: Absent. There are no delimiters or explicitly defined instructions forcing the agent to treat the
<body>placeholder string as plain data or text formatting only.\n - Capability inventory: Local directory creation (
mkdir -p) and file generation capability.\n - Sanitization: Absent. The instructions do not define any sanitization, escaping, or strict text processing rules prior to writing the
<body>variable data block into filesystem markdown documents.
Audit Metadata