to-tickets
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from various sources which could contain malicious instructions. \n
- Ingestion points: The agent is instructed to fetch and read the full body and comments of specs, issue numbers, or URLs provided by the user (SKILL.md). \n
- Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions within the ingested content. \n
- Capability inventory: The skill has the ability to write local files to the ".scratch/" directory and perform network requests to publish issues to platforms like GitHub or Linear (SKILL.md). \n
- Sanitization: No sanitization or validation logic is specified for the external content before it is used to generate ticket metadata or file structures.
Audit Metadata