skills/a-canary/arc-skills/to-tickets/Gen Agent Trust Hub

to-tickets

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements logical instructions for requirement analysis and task decomposition. Its primary operations, such as reading project documentation and writing to local or remote issue trackers, are transparent and align with its stated functionality for software development orchestration.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data which represents a potential attack surface, though this is a necessary feature for its intended purpose.
  • Ingestion points: SKILL.md (Step 1: Gather context) specifies that the agent should fetch and read the full body and comments from issue numbers or URLs provided in the conversation.
  • Boundary markers: Absent. The instructions do not specify the use of delimiters or 'ignore' commands when processing retrieved external content.
  • Capability inventory: The skill performs file system writes (writing tickets.md to the repo root) and network operations (fetching URLs and publishing to GitHub/Linear) as defined in SKILL.md.
  • Sanitization: Absent. There are no instructions for sanitizing or validating external content before it is parsed into the ticket drafting process.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 01:03 AM
Security Audit — agent-trust-hub — to-tickets