apex-tier1
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The validation scripts (
scripts/validate.shandscripts/validate.ps1) use dynamic command execution. Invalidate.sh, therun_stepfunction useseval "$cmd", where$cmdis constructed from strings likenpm run lintornpx eslint. Invalidate.ps1,Invoke-Expressionis used for similar purposes. While these commands are largely derived from static strings or local configuration files (package.json), they represent a shell execution surface that could be exploited if an attacker can influence the project's build configuration files. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted task descriptions from the user to generate pull request bodies and branch names.
- Ingestion points:
SKILL.mdinstructs the agent to parse a user-provided task description into acceptance criteria and use it ingh pr createcommands. - Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are provided when processing the task description.
- Capability inventory: The skill has capabilities for file system modification (
git), network operations via CLI (gh pr create,git push), and local script execution (scripts/validate.sh). - Sanitization: There is no evidence of sanitization for the
{task description}or{task-slug}before they are passed to shell commands likegit checkout -borgh pr create. An attacker-crafted task name could potentially lead to command injection if the agent does not properly escape the input.
Audit Metadata