to-tickets
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it ingests untrusted data and possesses write capabilities.
- Ingestion points: In
SKILL.md, the "Gather context" step instructions specify that the agent should work from existing conversation context and fetch the full body and comments of issues from provided URLs or spec paths. - Boundary markers: The instructions lack specific boundary markers or "ignore embedded instructions" directives to prevent the agent from following malicious commands found within the ingested external data.
- Capability inventory: The skill has the capability to perform local file writes in the
.scratch/directory and network operations to publish issues to remote trackers like GitHub or Linear. - Sanitization: There is no evidence of sanitization, validation, or escaping of external data before it is interpolated into the ticket templates or published.
Audit Metadata