sync-progress

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on the GitHub CLI (gh) to perform its core operations. It executes commands to interact with the GitHub API, including gh api to query and modify issue comments, and gh issue edit to update labels and assignees. These operations are essential to the skill's purpose of syncing project progress.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it retrieves and acts upon external data from GitHub issues.
  • Ingestion points: The script scripts/progress-comment.sh fetches lists of comments from GitHub issues using gh api. The skill's instructions in SKILL.md suggest that the agent read previous comment bodies when updating markers.
  • Boundary markers: No explicit boundary markers or isolation techniques are employed to differentiate between legitimate progress data and potentially malicious instructions embedded in a comment body by external users.
  • Capability inventory: Across SKILL.md and scripts/progress-comment.sh, the skill demonstrates the ability to write to the repository via the GitHub API, including patching comments and modifying issue metadata (assignments and labels).
  • Sanitization: There is no evidence of content sanitization or validation of the retrieved comment data before it is processed by the agent or used to regenerate comment bodies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:23 PM
Security Audit — agent-trust-hub — sync-progress