ticket-retro
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs read and write operations on local directories and uses standard developer tools (
gh,linearis,sqlite3). - [SAFE]: No remote code execution or network exfiltration to unauthorized domains was detected. Network activity is limited to official CLI tool interactions with GitHub and Linear APIs.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted text from friction logs (
thoughts/shared/friction/) and GitHub PR titles. This creates a theoretical surface for indirect prompt injection, but the risk is minimal given the developer-controlled data sources and the limited impact of the generated report. - [COMMAND_EXECUTION]: The skill executes shell scripts located within its own directory for data processing. These scripts are invoked with specific, controlled arguments and do not present a command injection risk.
Audit Metadata