work-intake

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a bash script in the 'Step 0: Project Board Readiness' section that executes several shell commands.
  • Uses git remote get-url to derive project ownership from the local repository.
  • Uses the GitHub CLI (gh project view and gh project field-list) to interact with external project boards.
  • Uses jq, sed, and grep for data processing.
  • Modifies the execution environment using export for project-related environment variables.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest arbitrary user work requests, creating a surface for indirect prompt injection.
  • Ingestion points: The skill processes raw natural language work requests from users to determine scope and deliverables.
  • Boundary markers: The instructions do not define specific delimiters or 'ignore' instructions for the incoming user request data.
  • Capability inventory: The skill has the capability to execute shell commands (as seen in Step 0) and record information into the agent's long-term memory (mcp__memory__create_entities).
  • Sanitization: The triage script uses double-quoting for shell variables and regular expressions for data extraction, which provides basic protection against simple command injection, but does not prevent the AI from following instructions embedded within a request.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:05 AM
Security Audit — agent-trust-hub — work-intake