close-epic
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub issue comments, sub-issue progress markers, and PR reviews to generate summaries and retrospective reports.
- Ingestion points: Data is ingested through
gh issue viewandgh pr viewcommands in SKILL.md (Steps 1, 2, and 3) and reference files. - Boundary markers: The skill uses HTML comments (e.g.,
<!-- sdd-summary -->,<!-- sdd-retro -->,<!-- sdd-feedback-draft -->) to distinguish its generated content from other issue data. - Capability inventory: The skill has the ability to close, edit, and create GitHub issues using the
ghCLI and can write documentation files to the local repository. - Sanitization: Step 5 and
references/skill-feedback.mddefine a comprehensive 'guard' that scans outbound feedback for sensitive data, including URLs, file paths, code blocks, and organization names, blocking any transmission that violates the allowlist. - [COMMAND_EXECUTION]: The skill performs extensive shell command execution using the
ghCLI and platform-provided scripts (e.g.,${CLAUDE_PLUGIN_ROOT}/scripts/sdd-retro.sh) to interact with the GitHub API and local environment. - [DATA_EXFILTRATION]: The skill includes a feature to file feedback issues to the vendor's repository (
syn54x/skills). This behavior is governed by strict consent rules (Step 5.1), requiring an explicit opt-in in configuration, and is protected by an automated data guard to ensure no sensitive internal project data is exfiltrated.
Audit Metadata