work-github-issue
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on local Git and GitHub CLI (
gh) commands to manage issue state and concurrency locks viarefs/notes/rca-issue-leases/. These operations are essential for the skill's documented purpose and are implemented using standard subprocess calls with internal validation. - [INDIRECT_PROMPT_INJECTION]: The skill parses GitHub issue bodies and comments for "Human action contracts" which determine when an agent can proceed with work. While this processes untrusted data, the implementation in
issue_lease.pyuses rigorous validation logic (checking for specific headings, meaningful text requirements, and recognized result tokens) to mitigate the risk of the agent following malicious instructions injected into issues. - Ingestion points: GitHub issue bodies and comments fetched via
gh issue view(e.g., inissue_lease.py). - Boundary markers: The script looks for explicit
## 사람에게 필요한 도움(Human action required) headings and HTML markers like<!-- work-github-issue:state role=... -->to delimit instructions. - Capability inventory: The skill can perform Git operations (commit, push, ref management) and GitHub operations (assignment, commenting, label management).
- Sanitization:
issue_lease.pyimplements a complex verification chain (human_action_contract_is_complete,suggested_comment_is_useful) that ensures contracts follow a strict schema and contain specific, non-generic tokens before they are considered valid. - [EXTERNAL_DOWNLOADS]: The skill interacts with
github.comvia standard developer tools. These interactions are consistent with the skill's primary function and target a well-known, trusted service.
Audit Metadata