to-issues
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external issue trackers (issue bodies, comments) and conversation context to generate new project issues. This creates a surface where embedded instructions in those sources could attempt to influence the agent's output.
- Ingestion points: SKILL.md (Step 1: Gather context) fetches full body and comments from issue tracker URLs or references.
- Boundary markers: Absent; the skill does not explicitly instruct the agent to ignore instructions embedded within the fetched issue data.
- Capability inventory: The skill has the capability to read from the issue tracker and publish new issues.
- Sanitization: Absent; content is processed directly into the drafting phase.
- Mitigation: The skill includes a mandatory human-in-the-loop step (Step 4: Quiz the user) where the user must review and approve the proposed breakdown before any issues are published, which mitigates the risk of unauthorized or malicious issue creation.
Audit Metadata