implement-issue
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill relies on retrieving and processing data from GitHub issues (body and comments), which are externally controlled ingestion points.
- Ingestion points: The skill uses
gh issue viewinSKILL.md(Step 1) to fetch the issue body, comments, and metadata. - Capability inventory: The agent is granted capabilities to execute shell commands (
git,gh) and modify the local filesystem during the development process. - Boundary markers: Although the skill instructs the agent to look for specific Markdown headers (e.g.,
## What to build,## Acceptance criteria), it lacks explicit instructions to ignore or validate instructions that might be embedded within those sections to override agent behavior. - Sanitization: There is no mention of sanitizing or escaping the content retrieved from the GitHub issue before the agent processes or executes instructions based on it.
- [DYNAMIC_EXECUTION]: The skill explicitly directs the agent to execute shell commands provided in the
## Verifysection of a GitHub issue verbatim. - Evidence:
SKILL.md(Step 5) states: "Run the ticket's ## Verify block, verbatim, from the repo root, on the committed state." - Risk: This design pattern allows for arbitrary command execution. If a malicious user creates or edits a GitHub issue to include harmful bash commands in the verification block, the agent will execute them in the environment where the skill is running.
- [COMMAND_EXECUTION]: The skill makes extensive use of system commands for repository management and interaction with GitHub.
- Evidence: Multiple calls to
git(fetch, switch, status, notes, push) andgh(issue view, issue edit, pr create) are used to perform the skill's primary functions.
Audit Metadata