work-intake
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a bash script in the 'Step 0: Project Board Readiness' section that executes several shell commands.
- Uses
git remote get-urlto derive project ownership from the local repository. - Uses the GitHub CLI (
gh project viewandgh project field-list) to interact with external project boards. - Uses
jq,sed, andgrepfor data processing. - Modifies the execution environment using
exportfor project-related environment variables. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest arbitrary user work requests, creating a surface for indirect prompt injection.
- Ingestion points: The skill processes raw natural language work requests from users to determine scope and deliverables.
- Boundary markers: The instructions do not define specific delimiters or 'ignore' instructions for the incoming user request data.
- Capability inventory: The skill has the capability to execute shell commands (as seen in Step 0) and record information into the agent's long-term memory (
mcp__memory__create_entities). - Sanitization: The triage script uses double-quoting for shell variables and regular expressions for data extraction, which provides basic protection against simple command injection, but does not prevent the AI from following instructions embedded within a request.
Audit Metadata