skills/syn54x/skills/implement-issue/Gen Agent Trust Hub

implement-issue

Fail

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill explicitly instructs the agent to execute a 'Verify' block of code extracted from an external GitHub issue body. The instructions state: 'Run the ticket's ## Verify block, verbatim, from the repo root'. This allows for arbitrary command execution controlled by the content of the GitHub issue.
  • [INDIRECT_PROMPT_INJECTION]: The skill is highly vulnerable to indirect prompt injection. It ingests untrusted data from GitHub issue titles, bodies, and comments (gh issue view) and uses this data to drive its logic and execution path without boundary markers or sanitization.
  • Ingestion points: The skill reads issue data using gh issue view "$N" --json number,title,url,body,state,labels,assignees,parent,blockedBy and gh issue view "$N" --comments in SKILL.md.
  • Boundary markers: None. The skill does not use delimiters or instructions to ignore embedded commands within the ingested issue body.
  • Capability inventory: The agent has access to the shell, git, and gh CLI, allowing it to modify repositories, push code, and create PRs.
  • Sanitization: None. The skill specifies 'verbatim' execution of the verification block, which is a direct execution of external content.
  • [DYNAMIC_EXECUTION]: The skill implements a workflow where the execution logic (the verification commands) is not defined in the skill itself but is loaded and run dynamically from a remote, mutable source (the GitHub issue body).
  • [REMOTE_CODE_EXECUTION]: By design, the skill facilitates the execution of remote content. If an attacker can label a malicious issue as ready-for-agent, they can achieve code execution on the environment where the agent is running.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 24, 2026, 02:28 AM
Security Audit — agent-trust-hub — implement-issue