setup-syn54x-skills

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the GitHub CLI (gh) to automate repository configuration, including label creation (needs-plan, ready-for-agent, etc.) and the management of organization-level issue types like 'Epic' and 'Task' via API calls.
  • [INDIRECT_PROMPT_INJECTION]: The skill inserts a 'Routing block' into the project's CLAUDE.md or AGENTS.md file. This block contains instructions that guide the agent's future planning and development behavior, such as prioritizing specific skills and disabling competing ones.
  • Ingestion points: Project configuration files (CLAUDE.md, AGENTS.md).
  • Boundary markers: The instructions are delimited by <!-- sdd-routing --> tags.
  • Capability inventory: The skill suite utilizes file modification and GitHub CLI commands.
  • Sanitization: Content is based on a static template within the skill package.
  • [EXTERNAL_DOWNLOADS]: The provided GitHub Action workflows (sdd-implement.yml, sdd-review.yml) configure the repository to fetch and execute plugins from the vendor's repository (https://github.com/syn54x/skills.git) during CI/CD processes. These workflows leverage the official anthropics/claude-code-action.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:21 AM
Security Audit — agent-trust-hub — setup-syn54x-skills