github-project-management
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill employs
npxto dynamically download and execute theruv-swarmandclaude-flowpackages from the NPM registry at runtime. These resources are associated with the skill author's toolset. - [COMMAND_EXECUTION]: The instructions make extensive use of the Bash shell and GitHub CLI (
gh) to perform repository operations, project board automation, and data processing withjq. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data from external GitHub sources which could contain malicious instructions.
- Ingestion points: Untrusted data is retrieved using
gh issue view,gh issue list, andgh project item-list. - Boundary markers: The skill does not define specific delimiters or instructional guardrails when interpolating issue content into agent tasks.
- Capability inventory: The agent possesses full access to GitHub MCP tools, Claude Flow swarm orchestration tools, Bash execution, and file writing capabilities.
- Sanitization: No explicit sanitization or filtering steps are present for the data retrieved from GitHub before it is passed to the swarm agents for processing.
Audit Metadata