issue-to-prompt

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill's functionality is limited to reading project documentation and writing a summary file within the local directory. It does not perform network operations, access sensitive credentials, or execute external scripts.
  • [PROMPT_INJECTION]: Evaluation of indirect prompt injection attack surface: 1. Ingestion points: The skill reads project-specific artifacts from 'docs/ai-native/' and 'AGENTS.md'. 2. Boundary markers: The output format uses markdown headers, though no explicit 'ignore instructions' delimiters are applied to the input content. 3. Capability inventory: Operations are limited to reading documentation and writing to 'docs/ai-native/07-issue-prompt.md'. It lacks network access or subprocess execution capabilities. 4. Sanitization: No sanitization is performed on the ingested content. Given the restricted capabilities, this surface presents minimal risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 04:19 AM
Security Audit — agent-trust-hub — issue-to-prompt