github-project-management

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill employs npx to dynamically download and execute the ruv-swarm and claude-flow packages from the NPM registry at runtime. These resources are associated with the skill author's toolset.
  • [COMMAND_EXECUTION]: The instructions make extensive use of the Bash shell and GitHub CLI (gh) to perform repository operations, project board automation, and data processing with jq.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data from external GitHub sources which could contain malicious instructions.
  • Ingestion points: Untrusted data is retrieved using gh issue view, gh issue list, and gh project item-list.
  • Boundary markers: The skill does not define specific delimiters or instructional guardrails when interpolating issue content into agent tasks.
  • Capability inventory: The agent possesses full access to GitHub MCP tools, Claude Flow swarm orchestration tools, Bash execution, and file writing capabilities.
  • Sanitization: No explicit sanitization or filtering steps are present for the data retrieved from GitHub before it is passed to the swarm agents for processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:38 AM
Security Audit — agent-trust-hub — github-project-management