setup-syn54x-skills
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands via
git,gh(GitHub CLI), andglab(GitLab CLI) to inspect repository configuration, manage issue labels, and create issue tracker infrastructure. - [INDIRECT_PROMPT_INJECTION]: The skill defines conventions in
issue-tracker-github.mdandissue-tracker-gitlab.mdwhere agents are instructed to read and process data from external, untrusted sources such as issue comments and pull request descriptions. - Ingestion points:
gh issue view,gh pr view,glab issue view(specified in tracker documentation templates). - Boundary markers: Not explicitly defined in the provided templates for external data ingestion.
- Capability inventory: The configured pipeline includes capabilities for code implementation (
implement-issue), review (review-pr), and progress tracking. - Sanitization: No explicit sanitization or filtering of external content is described in the templates.
- [EXTERNAL_DOWNLOADS]: The skill facilitates the setup of GitHub Action workflows (
sdd-implement.yml,sdd-review.yml) that download theclaude-code-actionand associated plugins from the vendor's repository on GitHub. - [DATA_EXFILTRATION]: Section D4 includes an optional "upstream feedback" mechanism that proposes reporting skill defect metadata to a central repository; the skill documentation specifies that this process requires human review and approval before any data is sent.
- [PROMPT_INJECTION]: The generated
sdd-routing-block.mdcontains instructions forCLAUDE.mdthat explicitly direct agents to disregard other brainstorming or plan-writing skills in favor of the provided pipeline tools. - [DYNAMIC_EXECUTION]: The skill generates and writes GitHub Action configuration files to
.github/workflows/that execute code at runtime using dynamically configured plugins and prompts.
Audit Metadata