build-epic
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads sub-issue bodies, epic plans, and comments from GitHub using
gh issue viewandgh apicalls. This untrusted external data is then interpolated into theWORKER-BRIEF.mdandWORKFLOW-TEMPLATE.jsfiles. Because the skill dispatches powerful worker agents to implement these tickets, an attacker who can modify the GitHub issue content could inject malicious instructions that override the agent's behavior. - Ingestion points:
SKILL.mdreads issue details and comments in the 'Preflight' and 'Ready queue' sections usingghcommands. - Boundary markers: The
WORKER-BRIEF.mdtemplate inserts the sub-issue body verbatim without using delimiters or specific instructions to the agent to treat the content as data rather than instructions. - Capability inventory: The skill dispatches agents via the
Agenttool and runs scripts via theWorkflowtool, both of which have capabilities to modify source code and execute shell commands. - Sanitization: No sanitization, escaping, or validation is performed on the content retrieved from GitHub.
- [COMMAND_EXECUTION]: The skill makes extensive use of the GitHub CLI (
gh) andgitto manage issues, pull requests, and local worktrees. It executes multiple shell scripts included with the skill (scripts/ready.sh) and usesgit worktreeto isolate concurrent worker environments. - [DYNAMIC_EXECUTION]: The skill uses
WORKFLOW-TEMPLATE.jsto generate dynamic workflows when the--workflowflag is passed. This JavaScript code is populated with ticket data at runtime and executed via the platform's workflow engine. Additionally, the skill dispatches sub-agents using harness-specific primitives like Claude Code'sAgentcall or Cursor's background agents.
Audit Metadata