skills/eszxcvfd/skills/to-tickets/Gen Agent Trust Hub

to-tickets

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill directs the agent to fetch and process content from external URLs or issue trackers provided by the user to gather context for ticket creation. This functionality creates an attack surface for indirect prompt injection, as malicious instructions could be embedded in the retrieved content to manipulate the agent's output or behavior.
  • Ingestion points: User-supplied references such as specification paths, issue numbers, or external URLs mentioned in SKILL.md.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' warnings to isolate external data from the agent's primary task instructions.
  • Capability inventory: The skill allows the agent to read sensitive local documentation (e.g., ARCHITECTURE.md), write files to a local .scratch/ directory, and publish tickets to external services like GitHub or Linear.
  • Sanitization: No validation or sanitization requirements are described for the data retrieved from external sources before it is incorporated into the ticket generation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 01:31 AM
Security Audit — agent-trust-hub — to-tickets