skills/syn54x/skills/sync-progress/Gen Agent Trust Hub

sync-progress

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the official GitHub CLI (gh) to perform API calls (gh api) and issue modifications (gh issue edit). These are standard commands used for automating GitHub workflows such as claiming issues and updating status comments.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for reading existing comments on a GitHub issue to locate a specific hidden HTML marker (e.g., <!-- sdd-progress -->). This represents an ingestion of external, potentially untrusted data from issue comments. However, the logic is limited to identifying the comment ID for the purpose of idempotent updates (PATCH/POST) and does not execute or interpret the content of the comments as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 02:28 AM
Security Audit — agent-trust-hub — sync-progress