ptlam-planning-tickets
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of feature specifications and repository evidence to generate ticket files. This creates a potential surface for indirect prompt injection where instructions embedded in the specification could influence the agent's file-writing actions.\n
- Ingestion points: Feature specifications and repository evidence (SKILL.md).\n
- Boundary markers: Not explicitly defined in the instructions for processing external content.\n
- Capability inventory: Creating directories and writing Markdown files (README.md, numbered tickets) (SKILL.md).\n
- Sanitization: No explicit sanitization or validation of the input specification content is mentioned before it is used to generate file content.
Audit Metadata