skills/nvidia/warp/warp-closing-issue/Gen Agent Trust Hub

warp-closing-issue

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external GitHub issues and comments using the gh CLI. This constitutes a surface for indirect prompt injection where an external attacker could place malicious instructions or code snippets within a GitHub issue that the agent then processes.
  • Ingestion points: The skill uses gh issue view to read issue bodies and comments in Step 2 of the resolving process.
  • Boundary markers: The instructions do not include specific delimiters or warnings to the agent to ignore instructions embedded within the issue content.
  • Capability inventory: The skill has high-privilege capabilities including the ability to write to GitHub (comments/closure), execute git commands, and run Python scripts via uv run.
  • Sanitization: While the skill provides safe CLI usage patterns (like avoiding @file injection), it does not specify sanitization of the untrusted text ingested from GitHub.
  • [DYNAMIC_EXECUTION]: The skill is explicitly instructed to generate and execute Python code based on external descriptions to verify bugs.
  • Evidence: Step 7 in SKILL.md directs the agent to "create one or more temporary scripts that exercise the reported behavior" and run them using uv run. If the source issue contains a malicious reproducer, the agent may execute it during this step.
  • [COMMAND_EXECUTION]: The skill relies on executing various system commands to perform code analysis, building, and GitHub interaction.
  • Evidence: The references/commands.md file defines several shell command patterns for gh, git, and uv, including rebuilding native libraries via build_lib.py.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:52 AM
Security Audit — agent-trust-hub — warp-closing-issue