to-issues
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by ingesting untrusted data from an external project management tool.\n
- Ingestion points: The skill fetches the full body and comments of issues from the issue tracker as described in the 'Gather context' step in SKILL.md.\n
- Boundary markers: Absent. The instructions do not define delimiters or provide guidance to the agent to distinguish between user-provided instructions and data fetched from the external source.\n
- Capability inventory: The skill is designed to read from the tracker and publish new issues, allowing potential malicious content from existing issues to influence the creation of new ones.\n
- Sanitization: Absent. There are no instructions to sanitize, escape, or validate the content retrieved from the issue tracker.
Audit Metadata