triage
Warn
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources which could contain malicious instructions. Ingestion points: Reads issue bodies, comments, and pull request diffs in SKILL.md. Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present in the triage workflow. Capability inventory: The skill has capabilities to write to files (e.g., .out-of-scope/ directory), post comments, close issues, and execute shell commands. Sanitization: While a disclaimer is added to AI-generated comments, there is no sanitization of the input data before processing or interpolation into prompts.
- [DYNAMIC_EXECUTION]: The skill instructs the agent to execute code from external, untrusted sources as part of its verification step. Evidence: SKILL.md contains the instruction: 'confirm the diff does what it claims: check it out, run the relevant tests or commands.' Risk: This practice allows for potential remote code execution (RCE) if a malicious pull request contains harmful code in its tests or initialization scripts that the agent executes during triage.
- [COMMAND_EXECUTION]: The skill instructs the agent to run or recommend specific commands. Evidence: SKILL.md mentions the command '/setup-matt-pocock-skills' for configuration mapping.
- [REMOTE_CODE_EXECUTION]: By instructing the agent to 'check out' and 'run relevant tests or commands' from an external pull request, the skill enables execution of code from a remote, untrusted source.
Audit Metadata