issue-create

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input to classify content and suggest labels using AI models, creating a vulnerability surface for indirect prompt injection.
  • Ingestion points: Untrusted data enters the agent context through the --body and --title CLI arguments used in the issue-create.ts script.
  • Boundary markers: The AI prompts defined in references/ai-prompts.md (e.g., Content: {content}) do not utilize explicit delimiters or 'ignore embedded instructions' warnings to separate user data from system instructions.
  • Capability inventory: The skill has access to the Bash tool and can perform GitHub operations via the gh CLI (gh issue create). It also leverages Playwright for browser-based image uploads.
  • Sanitization: There is no evidence of escaping, validation, or filtering of the external content before it is interpolated into AI prompts.
  • [PERSISTENCE]: The skill includes a 'Self-Evolving' mechanism that instructs the agent to modify the SKILL.md file based on its usage experiences.
  • The instructions ('fix this file immediately, don't defer') direct the agent to rewrite its own source instructions, which could lead to the persistence of malicious or unintended behavior if the agent is manipulated during a session.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 01:57 AM
Security Audit — agent-trust-hub — issue-create