github-project-management

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources such as GitHub issue bodies, comments, and project board items to drive automation and swarm behavior.
  • Ingestion points: The skill uses gh issue view, gh issue list, and gh project item-list in SKILL.md to retrieve potentially attacker-controlled content from GitHub repositories.
  • Boundary markers: The instructions do not define explicit boundary markers or instructions for the agent to ignore embedded commands within issue content.
  • Capability inventory: The skill possesses capabilities to write to the file system (Write, TodoWrite), execute shell commands, and modify GitHub repository state (creating/editing issues and project cards).
  • Sanitization: External content retrieved from GitHub is passed to analysis tools (e.g., npx ruv-swarm github analyze-stale) without explicit sanitization or escaping in the provided scripts.
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to execute tools from remote packages provided by the author.
  • Evidence: Multiple instances of npx claude-flow@alpha and npx ruv-swarm are present in SKILL.md.
  • Context: These packages are vendor-provided tools from the skill's author (ruvnet) designed for swarm orchestration and GitHub automation.
  • [REMOTE_CODE_EXECUTION]: The skill executes remote code via npx commands that download and run packages from the npm registry at runtime.
  • Evidence: Commands like npx ruv-swarm github board-sync and npx claude-flow@alpha hooks pre-task execute logic from external packages.
  • [COMMAND_EXECUTION]: The skill makes extensive use of shell command execution to interface with the GitHub CLI (gh) and Node.js environment.
  • Evidence: Systematic use of gh issue, gh project, and jq for project automation and data processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:12 AM
Security Audit — agent-trust-hub — github-project-management