kmp-github-issue-governance

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/gh_sub_issue.py utilizes subprocess.run to invoke the GitHub CLI (gh) for issue creation, listing, and modification. It dynamically builds command arguments from user-provided inputs like titles and labels.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes markdown payloads which may originate from untrusted sources, creating a potential surface for prompt injection.
  • Ingestion points: Markdown content read from files or stdin in scripts/gh_sub_issue.py and scripts/validate_issue_payload.py.
  • Boundary markers: The skill documentation strongly recommends using --body-file and temporary files to isolate markdown content from the shell environment.
  • Capability inventory: The skill can execute gh CLI commands (network and repository access) and read/write local files for payload handling.
  • Sanitization: The scripts/validate_issue_payload.py utility lints markdown for structural errors, such as unclosed backticks and escaped newline artifacts, which helps prevent accidental command interpretation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 10:23 AM
Security Audit — agent-trust-hub — kmp-github-issue-governance