warp-closing-issue
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external GitHub issues and comments using the
ghCLI. This constitutes a surface for indirect prompt injection where an external attacker could place malicious instructions or code snippets within a GitHub issue that the agent then processes. - Ingestion points: The skill uses
gh issue viewto read issue bodies and comments in Step 2 of the resolving process. - Boundary markers: The instructions do not include specific delimiters or warnings to the agent to ignore instructions embedded within the issue content.
- Capability inventory: The skill has high-privilege capabilities including the ability to write to GitHub (comments/closure), execute git commands, and run Python scripts via
uv run. - Sanitization: While the skill provides safe CLI usage patterns (like avoiding
@fileinjection), it does not specify sanitization of the untrusted text ingested from GitHub. - [DYNAMIC_EXECUTION]: The skill is explicitly instructed to generate and execute Python code based on external descriptions to verify bugs.
- Evidence: Step 7 in
SKILL.mddirects the agent to "create one or more temporary scripts that exercise the reported behavior" and run them usinguv run. If the source issue contains a malicious reproducer, the agent may execute it during this step. - [COMMAND_EXECUTION]: The skill relies on executing various system commands to perform code analysis, building, and GitHub interaction.
- Evidence: The
references/commands.mdfile defines several shell command patterns forgh,git, anduv, including rebuilding native libraries viabuild_lib.py.
Audit Metadata