issue-create
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input to classify content and suggest labels using AI models, creating a vulnerability surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the agent context through the
--bodyand--titleCLI arguments used in theissue-create.tsscript. - Boundary markers: The AI prompts defined in
references/ai-prompts.md(e.g.,Content: {content}) do not utilize explicit delimiters or 'ignore embedded instructions' warnings to separate user data from system instructions. - Capability inventory: The skill has access to the
Bashtool and can perform GitHub operations via theghCLI (gh issue create). It also leverages Playwright for browser-based image uploads. - Sanitization: There is no evidence of escaping, validation, or filtering of the external content before it is interpolated into AI prompts.
- [PERSISTENCE]: The skill includes a 'Self-Evolving' mechanism that instructs the agent to modify the
SKILL.mdfile based on its usage experiences. - The instructions ('fix this file immediately, don't defer') direct the agent to rewrite its own source instructions, which could lead to the persistence of malicious or unintended behavior if the agent is manipulated during a session.
Audit Metadata