work-on-issues

Fail

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill contains explicit instructions to copy .env and .env.* files from the main working directory into subdirectories (.claude/worktrees/issue-<number>) and propagate modified versions back to the root. These files typically contain sensitive information like API keys, database credentials, and private secrets. Moving these files between directories increases the attack surface for credential exposure, especially if the target directories are not correctly secured or if the agent context is leaked.
  • [INDIRECT_PROMPT_INJECTION]: The workflow involves fetching issue titles, bodies, and comments from GitHub or GitLab and passing them directly into prompt templates for sub-agents ("Implement issue #: "). This creates a vulnerability where an external attacker could craft a malicious issue or comment containing instructions to override the agent's behavior, steal data, or perform unauthorized actions.
  • Ingestion points: Fetches data from GitHub/GitLab via gh issue list, gh issue view --comments, glab issue list, and glab issue view --comments.
  • Boundary markers: None identified. The prompt templates interpolate external variables like <title> and <AC> without delimiters or instructions to ignore embedded commands.
  • Capability inventory: The skill has access to the filesystem (git worktree, cp), execution of external packages (npx fallow), and network-enabled CLI tools (gh, glab) with the ability to merge PRs and post comments.
  • Sanitization: The skill does not describe any validation or sanitization of the fetched issue content before processing.
  • [EXTERNAL_DOWNLOADS]: The implementation phase suggests running npx fallow audit for TypeScript or JavaScript projects, including instructions to install the package if it is not present. This introduces a dependency on an external package from a public registry, which could be exploited through supply chain attacks if the package is compromised or substituted.
  • [COMMAND_EXECUTION]: The skill makes extensive use of shell commands and scripts to manage git worktree and file operations. While the provided scripts are structured, they rely on variables derived from issue numbers and labels, which could lead to command injection if the underlying agent platform fails to properly escape these parameters.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 12, 2026, 02:47 AM