implement-issue

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill relies on retrieving and processing data from GitHub issues (body and comments), which are externally controlled ingestion points.
  • Ingestion points: The skill uses gh issue view in SKILL.md (Step 1) to fetch the issue body, comments, and metadata.
  • Capability inventory: The agent is granted capabilities to execute shell commands (git, gh) and modify the local filesystem during the development process.
  • Boundary markers: Although the skill instructs the agent to look for specific Markdown headers (e.g., ## What to build, ## Acceptance criteria), it lacks explicit instructions to ignore or validate instructions that might be embedded within those sections to override agent behavior.
  • Sanitization: There is no mention of sanitizing or escaping the content retrieved from the GitHub issue before the agent processes or executes instructions based on it.
  • [DYNAMIC_EXECUTION]: The skill explicitly directs the agent to execute shell commands provided in the ## Verify section of a GitHub issue verbatim.
  • Evidence: SKILL.md (Step 5) states: "Run the ticket's ## Verify block, verbatim, from the repo root, on the committed state."
  • Risk: This design pattern allows for arbitrary command execution. If a malicious user creates or edits a GitHub issue to include harmful bash commands in the verification block, the agent will execute them in the environment where the skill is running.
  • [COMMAND_EXECUTION]: The skill makes extensive use of system commands for repository management and interaction with GitHub.
  • Evidence: Multiple calls to git (fetch, switch, status, notes, push) and gh (issue view, issue edit, pr create) are used to perform the skill's primary functions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 05:41 PM
Security Audit — agent-trust-hub — implement-issue