skills/syn54x/skills/build-epic/Gen Agent Trust Hub

build-epic

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub issues and comments using the gh CLI. This data is used to compute task layers and is passed directly into worker agent prompts via the references/worker-brief.md template. Maliciously crafted issue content could potentially influence the orchestrator or worker agents.
  • Ingestion points: SKILL.md and references/workflow-template.js via GitHub CLI commands.
  • Boundary markers: Uses markdown headers and specific HTML comment markers (e.g., <!-- sdd-plan -->) for structural delimitation.
  • Capability inventory: Shell command execution (git, gh), multi-agent dispatch (Agent(), Delegate), and dynamic workflow execution (Workflow tool).
  • Sanitization: Lacks explicit sanitization of issue bodies or comments before prompt interpolation.
  • [DYNAMIC_EXECUTION]: When the --workflow flag is used, the skill generates and executes a JavaScript script (references/workflow-template.js) using the environment's Workflow tool to programmatically manage complex agent orchestration and merge ordering.
  • [COMMAND_EXECUTION]: The skill performs numerous shell operations to manage the repository state, including creating branches, pushing to remotes, and using the GitHub CLI to interact with issue and PR metadata. It also facilitates isolated agent environments through git worktrees.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 02:28 AM
Security Audit — agent-trust-hub — build-epic