to-tickets

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process potentially untrusted data from external sources (such as GitHub or Linear issue bodies and comments) and local codebase files. This ingestion creates a surface where instructions hidden within these sources could attempt to override the agent's behavior. However, the skill explicitly mandates a human-in-the-loop 'Quiz the user' phase where the proposed breakdown must be reviewed and approved before any automated actions are taken.
  • Ingestion points: External issue tracker URLs, spec paths, and conversation context (SKILL.md Step 1).
  • Boundary markers: None explicitly defined to isolate processed external data from internal logic.
  • Capability inventory: Ability to write local files in the .scratch/ directory and publish issues to external platforms like GitHub or Linear (SKILL.md Step 5).
  • Sanitization: Relies on model-level safety filters and a required manual approval step by the user before final execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 10:40 AM
Security Audit — agent-trust-hub — to-tickets