kmp-github-issue-governance
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/gh_sub_issue.pyutilizessubprocess.runto invoke the GitHub CLI (gh) for issue creation, listing, and modification. It dynamically builds command arguments from user-provided inputs like titles and labels. - [INDIRECT_PROMPT_INJECTION]: The skill processes markdown payloads which may originate from untrusted sources, creating a potential surface for prompt injection.
- Ingestion points: Markdown content read from files or stdin in
scripts/gh_sub_issue.pyandscripts/validate_issue_payload.py. - Boundary markers: The skill documentation strongly recommends using
--body-fileand temporary files to isolate markdown content from the shell environment. - Capability inventory: The skill can execute
ghCLI commands (network and repository access) and read/write local files for payload handling. - Sanitization: The
scripts/validate_issue_payload.pyutility lints markdown for structural errors, such as unclosed backticks and escaped newline artifacts, which helps prevent accidental command interpretation.
Audit Metadata