github-project-management
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources such as GitHub issue bodies, comments, and project board items to drive automation and swarm behavior.
- Ingestion points: The skill uses
gh issue view,gh issue list, andgh project item-listinSKILL.mdto retrieve potentially attacker-controlled content from GitHub repositories. - Boundary markers: The instructions do not define explicit boundary markers or instructions for the agent to ignore embedded commands within issue content.
- Capability inventory: The skill possesses capabilities to write to the file system (
Write,TodoWrite), execute shell commands, and modify GitHub repository state (creating/editing issues and project cards). - Sanitization: External content retrieved from GitHub is passed to analysis tools (e.g.,
npx ruv-swarm github analyze-stale) without explicit sanitization or escaping in the provided scripts. - [EXTERNAL_DOWNLOADS]: The skill uses
npxto execute tools from remote packages provided by the author. - Evidence: Multiple instances of
npx claude-flow@alphaandnpx ruv-swarmare present inSKILL.md. - Context: These packages are vendor-provided tools from the skill's author (
ruvnet) designed for swarm orchestration and GitHub automation. - [REMOTE_CODE_EXECUTION]: The skill executes remote code via
npxcommands that download and run packages from the npm registry at runtime. - Evidence: Commands like
npx ruv-swarm github board-syncandnpx claude-flow@alpha hooks pre-taskexecute logic from external packages. - [COMMAND_EXECUTION]: The skill makes extensive use of shell command execution to interface with the GitHub CLI (
gh) and Node.js environment. - Evidence: Systematic use of
gh issue,gh project, andjqfor project automation and data processing.
Audit Metadata