bug-tracker
Warn
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill accesses and copies sensitive environment files (
.env,.env.*) between the root directory and isolated worktrees. This practice exposes potential secrets to the agent's task-specific environments. - Evidence: Step 3 ("Copy .env files") and Step 5 ("Propagate .env files back") in
SKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from public GitHub issues and includes it in prompts for subagents, creating a vulnerability to adversarial instructions hidden in bug reports.
- Ingestion points: Fetches issue descriptions and comments from GitHub via
gh issue viewinSKILL.md. - Boundary markers: Uses structural headers in the subagent prompt (e.g., "Issue body (verbatim):") but lacks explicit instructions to ignore potentially malicious content within that data.
- Capability inventory: Access to
gitfor repository management,ghfor tracker interaction,curlfor file downloads, andnpxfor package execution. - Sanitization: There is no evidence of input validation or content filtering for the data retrieved from the external tracker.
- [EXTERNAL_DOWNLOADS]: The skill downloads sample files and logs from arbitrary URLs provided in issue reports and suggests installing packages at runtime.
- Evidence: Use of
curlto fetch attachments from user-provided URLs in Step 2.2 and instructions to runnpx fallow auditin Step 4. - [COMMAND_EXECUTION]: The workflow relies on shell commands for repository and issue management, which could be exploited if parameters like issue content or repository names are manipulated.
- Evidence: Shell blocks using
gh,git, andcpthroughoutSKILL.md.
Audit Metadata