skills/rca32/skills/work-github-issue/Gen Agent Trust Hub

work-github-issue

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on local Git and GitHub CLI (gh) commands to manage issue state and concurrency locks via refs/notes/rca-issue-leases/. These operations are essential for the skill's documented purpose and are implemented using standard subprocess calls with internal validation.
  • [INDIRECT_PROMPT_INJECTION]: The skill parses GitHub issue bodies and comments for "Human action contracts" which determine when an agent can proceed with work. While this processes untrusted data, the implementation in issue_lease.py uses rigorous validation logic (checking for specific headings, meaningful text requirements, and recognized result tokens) to mitigate the risk of the agent following malicious instructions injected into issues.
  • Ingestion points: GitHub issue bodies and comments fetched via gh issue view (e.g., in issue_lease.py).
  • Boundary markers: The script looks for explicit ## 사람에게 필요한 도움 (Human action required) headings and HTML markers like <!-- work-github-issue:state role=... --> to delimit instructions.
  • Capability inventory: The skill can perform Git operations (commit, push, ref management) and GitHub operations (assignment, commenting, label management).
  • Sanitization: issue_lease.py implements a complex verification chain (human_action_contract_is_complete, suggested_comment_is_useful) that ensures contracts follow a strict schema and contain specific, non-generic tokens before they are considered valid.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with github.com via standard developer tools. These interactions are consistent with the skill's primary function and target a well-known, trusted service.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 03:26 AM
Security Audit — agent-trust-hub — work-github-issue