prepare-issue
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it processes untrusted data from GitHub issues and pull requests.
- Ingestion points: The agent ingests external content from issue bodies, comments, and pull request diffs in SKILL.md.
- Boundary markers: The skill instructions do not define clear delimiters or specific instructions for the agent to ignore potentially malicious commands embedded within the ingested data.
- Capability inventory: The agent is tasked with verifying claims by executing reproduction commands or scripts in SKILL.md, which creates a potential execution vector for injected instructions.
- Sanitization: The skill lacks explicit sanitization, validation, or filtering of external content before it is processed by the agent.
Audit Metadata