sweep-tickets
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from ticket stores and configuration files to determine workflow state.
- Ingestion points:
tickets/store-config.md,TICKET_CONVENTION.md,AUTOMATED_EXECUTION.md, and ticket metadata items. - Boundary markers: Not explicitly defined in the instructions.
- Capability inventory: File system read access and invocation of the
run-ticketskill. - Sanitization: The skill implements validation logic that halts execution if the store, identity, or policy context is missing or ambiguous.
- [SAFE]: The skill instructions emphasize safety by limiting operations to a single ticket per invocation and explicitly separating selection logic from execution to prevent unintended state mutations.
Audit Metadata