bug-tracker

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses and copies sensitive environment files (.env, .env.*) between the root directory and isolated worktrees. This practice exposes potential secrets to the agent's task-specific environments.
  • Evidence: Step 3 ("Copy .env files") and Step 5 ("Propagate .env files back") in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from public GitHub issues and includes it in prompts for subagents, creating a vulnerability to adversarial instructions hidden in bug reports.
  • Ingestion points: Fetches issue descriptions and comments from GitHub via gh issue view in SKILL.md.
  • Boundary markers: Uses structural headers in the subagent prompt (e.g., "Issue body (verbatim):") but lacks explicit instructions to ignore potentially malicious content within that data.
  • Capability inventory: Access to git for repository management, gh for tracker interaction, curl for file downloads, and npx for package execution.
  • Sanitization: There is no evidence of input validation or content filtering for the data retrieved from the external tracker.
  • [EXTERNAL_DOWNLOADS]: The skill downloads sample files and logs from arbitrary URLs provided in issue reports and suggests installing packages at runtime.
  • Evidence: Use of curl to fetch attachments from user-provided URLs in Step 2.2 and instructions to run npx fallow audit in Step 4.
  • [COMMAND_EXECUTION]: The workflow relies on shell commands for repository and issue management, which could be exploited if parameters like issue content or repository names are manipulated.
  • Evidence: Shell blocks using gh, git, and cp throughout SKILL.md.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 02:47 AM