setup-syn54x-skills

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands via git, gh (GitHub CLI), and glab (GitLab CLI) to inspect repository configuration, manage issue labels, and create issue tracker infrastructure.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines conventions in issue-tracker-github.md and issue-tracker-gitlab.md where agents are instructed to read and process data from external, untrusted sources such as issue comments and pull request descriptions.
  • Ingestion points: gh issue view, gh pr view, glab issue view (specified in tracker documentation templates).
  • Boundary markers: Not explicitly defined in the provided templates for external data ingestion.
  • Capability inventory: The configured pipeline includes capabilities for code implementation (implement-issue), review (review-pr), and progress tracking.
  • Sanitization: No explicit sanitization or filtering of external content is described in the templates.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the setup of GitHub Action workflows (sdd-implement.yml, sdd-review.yml) that download the claude-code-action and associated plugins from the vendor's repository on GitHub.
  • [DATA_EXFILTRATION]: Section D4 includes an optional "upstream feedback" mechanism that proposes reporting skill defect metadata to a central repository; the skill documentation specifies that this process requires human review and approval before any data is sent.
  • [PROMPT_INJECTION]: The generated sdd-routing-block.md contains instructions for CLAUDE.md that explicitly direct agents to disregard other brainstorming or plan-writing skills in favor of the provided pipeline tools.
  • [DYNAMIC_EXECUTION]: The skill generates and writes GitHub Action configuration files to .github/workflows/ that execute code at runtime using dynamically configured plugins and prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:23 PM
Security Audit — agent-trust-hub — setup-syn54x-skills