build-epic
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub issues and comments using the
ghCLI. This data is used to compute task layers and is passed directly into worker agent prompts via thereferences/worker-brief.mdtemplate. Maliciously crafted issue content could potentially influence the orchestrator or worker agents. - Ingestion points:
SKILL.mdandreferences/workflow-template.jsvia GitHub CLI commands. - Boundary markers: Uses markdown headers and specific HTML comment markers (e.g.,
<!-- sdd-plan -->) for structural delimitation. - Capability inventory: Shell command execution (git, gh), multi-agent dispatch (Agent(), Delegate), and dynamic workflow execution (Workflow tool).
- Sanitization: Lacks explicit sanitization of issue bodies or comments before prompt interpolation.
- [DYNAMIC_EXECUTION]: When the
--workflowflag is used, the skill generates and executes a JavaScript script (references/workflow-template.js) using the environment'sWorkflowtool to programmatically manage complex agent orchestration and merge ordering. - [COMMAND_EXECUTION]: The skill performs numerous shell operations to manage the repository state, including creating branches, pushing to remotes, and using the GitHub CLI to interact with issue and PR metadata. It also facilitates isolated agent environments through git worktrees.
Audit Metadata