bulk-issues
Pass
Audited by Gen Agent Trust Hub on May 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs extensive shell command execution using the
ghCLI for issue management, PR creation, and GraphQL API interactions. It also executes standard project lifecycle scripts includingpnpm lint,pnpm test,pnpm build, andpnpm test:e2e. While these are functional requirements, they represent a broad execution surface directed by agent reasoning. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests untrusted data from external sources. Specifically, it reads GitHub issue titles, bodies, and comments to 'parse requirements' and 'design the approach' for code modifications. An attacker could craft a malicious issue containing hidden instructions to influence the agent's behavior during the implementation phase.
- Ingestion points:
workflows/issue-task-loop.md(fetches issue metadata and body viagh issue view). - Boundary markers: No specific delimiters or instructions to ignore embedded commands are used when processing the ingested issue text.
- Capability inventory: The skill possesses the ability to edit local files, execute shell commands, and interact with the GitHub API.
- Sanitization: No sanitization or validation logic is present to filter malicious instructions within the issue content before the agent processes them.
Audit Metadata