to-tickets
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data which could potentially contain malicious instructions intended to manipulate agent behavior.
- Ingestion points: The skill fetches and reads full bodies and comments from user-provided references, such as specification paths, issue numbers, or URLs, as described in the 'Gather context' section of
SKILL.md. - Boundary markers: There are no instructions for the agent to use delimiters or specific safety warnings to ignore embedded instructions within the fetched external data.
- Capability inventory: The skill has access to powerful system tools including
Bash,Write,Edit,Read,Grep, andGlob, which increases the potential impact of a successful prompt injection. - Sanitization: No validation, escaping, or filtering mechanisms are defined for the content retrieved from external sources before it is processed by the agent.
Audit Metadata