Set up, explain, and change a Tessl factory on a repository: pick automations that fit how you work, such as triaging tickets, shipping tickets as pull requests, keeping pull requests moving, code review, and scheduled jobs.
78
98%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
Low
Low-risk findings worth noting
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
The workflow requires reading open GitHub issues (`gh issue list`) and repository contents, which can contain outsider-authored free text.
github.com
domain · 8 sites
The plugin instructs the agent to run `gh` CLI commands that fetch repository data, issues, PRs, and comments from GitHub at runtime; this content is outsider-authored free text that the agent then reads and acts on, creating indirect prompt-injection risk.