triage-issues
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted, human-written content from issue trackers (reports, attachments, comments) to drive code implementation and specification writing. This creates a surface where malicious instructions in an issue could influence the agent's actions.
- Ingestion points:
SKILL.mdspecifies reading the original report, attachments, comments, and related issues (e.g., from Linear or GitHub). - Boundary markers: Output is delimited using HTML comments (e.g.,
<!-- triage-issues:section:start -->), but there are no explicit boundary markers or instruction-filtering protocols defined for the ingestion of the issue content itself. - Capability inventory: The skill possesses the capability to write files (
scripts/body-sections.py), execute Git commands and network operations (scripts/claim.sh), and implement code changes or specifications based on the analyzed input. - Sanitization: The instructions include a manual check ("Check media for sensitive data before sharing it"), but there is no automated sanitization or escaping of the ingested issue text before it is interpolated into the agent's reasoning process.
- [COMMAND_EXECUTION]: The skill relies on custom utility scripts to manage its state and lifecycle.
- Evidence: It executes
scripts/claim.sh, which utilizes various Git subcommands (rev-parse,hash-object,ls-remote,commit-tree,push) to create a distributed locking mechanism via remote Git references. - Evidence: It executes
scripts/body-sections.pyto perform targeted updates to issue descriptions, which involves reading and writing file content based on arguments. - [DATA_EXFILTRATION]: The skill is instructed to share evidence, such as screenshots or logs, which could inadvertently contain sensitive information from the development environment.
- Evidence: The skill explicitly warns to "Check media for sensitive data before sharing it," acknowledging the risk of data exposure when routing reports to human decision-makers or external trackers.
Audit Metadata