setup-issue-tracker
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external or user-controlled sources, such as issue titles, bodies, and project specification files (
spec.md). - Ingestion points: The agent reads existing issue data via tools (e.g.,
ghCLI) and parses files likespec.md,AGENTS.md, andCLAUDE.md(as seen inSKILL.mdandtemplates/github.md). - Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from accidentally interpreting instructions embedded within the processed data.
- Capability inventory: The skill enables the agent to write to sensitive project instruction files (
AGENTS.md,CLAUDE.md) and execute shell commands via the GitHub CLI (gh) or Linear tools. - Sanitization: The instructions do not specify any sanitization, validation, or escaping of the content read from external issues before it is written to local files or used in command arguments.
- [COMMAND_EXECUTION]: The skill provides templates (
templates/github.md) containing complex shell commands involvinggh apiandjqfilters. These commands are intended for the agent to use in managing the repository's issue tracker. While these are legitimate management operations, providing executable command strings to an agent constitutes a command execution surface that requires careful handling of parameters like issue titles or slugs to avoid unintended shell behavior.
Audit Metadata