create-ticket
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection by ingesting data from external files and existing tickets to guide its actions.\n
- Ingestion points: The skill reads configuration from
docs/agents/bb-skills.mdand inspects existing project tickets to determine placement and identify duplicates.\n - Boundary markers: No specific delimiters or instructions to ignore instructions embedded in the ingested data are present.\n
- Capability inventory: The skill possesses the ability to read project state and create, modify, or move tickets using tracker tools.\n
- Sanitization: The skill does not explicitly validate or sanitize content retrieved from the tracker before using it to infer logic (e.g., for release grouping or project positioning).
Audit Metadata