implement-issue
Fail
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill explicitly instructs the agent to execute a 'Verify' block of code extracted from an external GitHub issue body. The instructions state: 'Run the ticket's ## Verify block, verbatim, from the repo root'. This allows for arbitrary command execution controlled by the content of the GitHub issue.
- [INDIRECT_PROMPT_INJECTION]: The skill is highly vulnerable to indirect prompt injection. It ingests untrusted data from GitHub issue titles, bodies, and comments (
gh issue view) and uses this data to drive its logic and execution path without boundary markers or sanitization. - Ingestion points: The skill reads issue data using
gh issue view "$N" --json number,title,url,body,state,labels,assignees,parent,blockedByandgh issue view "$N" --commentsinSKILL.md. - Boundary markers: None. The skill does not use delimiters or instructions to ignore embedded commands within the ingested issue body.
- Capability inventory: The agent has access to the shell,
git, andghCLI, allowing it to modify repositories, push code, and create PRs. - Sanitization: None. The skill specifies 'verbatim' execution of the verification block, which is a direct execution of external content.
- [DYNAMIC_EXECUTION]: The skill implements a workflow where the execution logic (the verification commands) is not defined in the skill itself but is loaded and run dynamically from a remote, mutable source (the GitHub issue body).
- [REMOTE_CODE_EXECUTION]: By design, the skill facilitates the execution of remote content. If an attacker can label a malicious issue as
ready-for-agent, they can achieve code execution on the environment where the agent is running.
Recommendations
- AI detected serious security threats
Audit Metadata