skills/syn54x/skills/close-epic/Gen Agent Trust Hub

close-epic

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub issue comments, sub-issue progress markers, and PR reviews to generate summaries and retrospective reports.
  • Ingestion points: Data is ingested through gh issue view and gh pr view commands in SKILL.md (Steps 1, 2, and 3) and reference files.
  • Boundary markers: The skill uses HTML comments (e.g., <!-- sdd-summary -->, <!-- sdd-retro -->, <!-- sdd-feedback-draft -->) to distinguish its generated content from other issue data.
  • Capability inventory: The skill has the ability to close, edit, and create GitHub issues using the gh CLI and can write documentation files to the local repository.
  • Sanitization: Step 5 and references/skill-feedback.md define a comprehensive 'guard' that scans outbound feedback for sensitive data, including URLs, file paths, code blocks, and organization names, blocking any transmission that violates the allowlist.
  • [COMMAND_EXECUTION]: The skill performs extensive shell command execution using the gh CLI and platform-provided scripts (e.g., ${CLAUDE_PLUGIN_ROOT}/scripts/sdd-retro.sh) to interact with the GitHub API and local environment.
  • [DATA_EXFILTRATION]: The skill includes a feature to file feedback issues to the vendor's repository (syn54x/skills). This behavior is governed by strict consent rules (Step 5.1), requiring an explicit opt-in in configuration, and is protected by an automated data guard to ensure no sensitive internal project data is exfiltrated.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 04:34 PM
Security Audit — agent-trust-hub — close-epic