close-epic

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub sub-issues, PR reviews, and comments to compute metrics and generate summaries.\n
  • Ingestion points: Data is ingested via gh issue view, gh pr view, and gh api calls in SKILL.md, RETRO.md, and scripts/sdd-retro.sh.\n
  • Boundary markers: The skill uses jq and specific string patterns (e.g., <!-- sdd-wave -->, ## Spec: FAIL) to parse data, though these are not cryptographic boundaries.\n
  • Capability inventory: The skill can create/close GitHub issues and execute local scripts (sdd-retro.sh, feedback-guard.sh).\n
  • Sanitization: Outbound feedback is processed through scripts/feedback-guard.sh, which checks for leaked URLs, code blocks, paths, and sensitive keywords.\n- [COMMAND_EXECUTION]: The skill relies on the gh (GitHub CLI) tool and local shell scripts for core functionality.\n
  • Evidence: Shell blocks in SKILL.md and RETRO.md invoke gh for repository and issue management.\n
  • Evidence: The skill executes scripts/sdd-retro.sh and scripts/feedback-guard.sh during the closing process.\n- [DATA_EXFILTRATION]: The skill provides an optional feature to send feedback to a vendor-controlled repository.\n
  • Evidence: SKILL-FEEDBACK.md details how to file issues at syn54x/skills-plus-plus using gh issue create.\n
  • Note: This feature is opt-in, requires explicit user consent, and is gated by a security guard script to prevent sensitive data leakage.\n- [DYNAMIC_EXECUTION]: Local scripts use runtime code execution for data processing tasks.\n
  • Evidence: scripts/sdd-retro.sh uses python3 -c snippets to perform time calculations and statistical analysis on metrics gathered from GitHub.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 05:41 PM
Security Audit — agent-trust-hub — close-epic