setup-issue-tracker

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external or user-controlled sources, such as issue titles, bodies, and project specification files (spec.md).
  • Ingestion points: The agent reads existing issue data via tools (e.g., gh CLI) and parses files like spec.md, AGENTS.md, and CLAUDE.md (as seen in SKILL.md and templates/github.md).
  • Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from accidentally interpreting instructions embedded within the processed data.
  • Capability inventory: The skill enables the agent to write to sensitive project instruction files (AGENTS.md, CLAUDE.md) and execute shell commands via the GitHub CLI (gh) or Linear tools.
  • Sanitization: The instructions do not specify any sanitization, validation, or escaping of the content read from external issues before it is written to local files or used in command arguments.
  • [COMMAND_EXECUTION]: The skill provides templates (templates/github.md) containing complex shell commands involving gh api and jq filters. These commands are intended for the agent to use in managing the repository's issue tracker. While these are legitimate management operations, providing executable command strings to an agent constitutes a command execution surface that requires careful handling of parameters like issue titles or slugs to avoid unintended shell behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 09:26 AM
Security Audit — agent-trust-hub — setup-issue-tracker