sync-progress
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on the GitHub CLI (
gh) to perform its core operations. It executes commands to interact with the GitHub API, includinggh apito query and modify issue comments, andgh issue editto update labels and assignees. These operations are essential to the skill's purpose of syncing project progress. - [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it retrieves and acts upon external data from GitHub issues.
- Ingestion points: The script
scripts/progress-comment.shfetches lists of comments from GitHub issues usinggh api. The skill's instructions inSKILL.mdsuggest that the agent read previous comment bodies when updating markers. - Boundary markers: No explicit boundary markers or isolation techniques are employed to differentiate between legitimate progress data and potentially malicious instructions embedded in a comment body by external users.
- Capability inventory: Across
SKILL.mdandscripts/progress-comment.sh, the skill demonstrates the ability to write to the repository via the GitHub API, including patching comments and modifying issue metadata (assignments and labels). - Sanitization: There is no evidence of content sanitization or validation of the retrieved comment data before it is processed by the agent or used to regenerate comment bodies.
Audit Metadata