build-epic

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads sub-issue bodies, epic plans, and comments from GitHub using gh issue view and gh api calls. This untrusted external data is then interpolated into the WORKER-BRIEF.md and WORKFLOW-TEMPLATE.js files. Because the skill dispatches powerful worker agents to implement these tickets, an attacker who can modify the GitHub issue content could inject malicious instructions that override the agent's behavior.
  • Ingestion points: SKILL.md reads issue details and comments in the 'Preflight' and 'Ready queue' sections using gh commands.
  • Boundary markers: The WORKER-BRIEF.md template inserts the sub-issue body verbatim without using delimiters or specific instructions to the agent to treat the content as data rather than instructions.
  • Capability inventory: The skill dispatches agents via the Agent tool and runs scripts via the Workflow tool, both of which have capabilities to modify source code and execute shell commands.
  • Sanitization: No sanitization, escaping, or validation is performed on the content retrieved from GitHub.
  • [COMMAND_EXECUTION]: The skill makes extensive use of the GitHub CLI (gh) and git to manage issues, pull requests, and local worktrees. It executes multiple shell scripts included with the skill (scripts/ready.sh) and uses git worktree to isolate concurrent worker environments.
  • [DYNAMIC_EXECUTION]: The skill uses WORKFLOW-TEMPLATE.js to generate dynamic workflows when the --workflow flag is passed. This JavaScript code is populated with ticket data at runtime and executed via the platform's workflow engine. Additionally, the skill dispatches sub-agents using harness-specific primitives like Claude Code's Agent call or Cursor's background agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 05:40 PM
Security Audit — agent-trust-hub — build-epic