ticket
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
verifycommand inscripts/ticket_cli.pyexecutes shell commands provided as arguments via the--cmdflag. It usessubprocess.run(command, shell=True), allowing for arbitrary local command execution as a method of providing work verification. - [COMMAND_EXECUTION]: The skill uses
subprocess.runto delegate functionality to established tools includinggitandgh(GitHub CLI) for repository state management and issue manipulation inscripts/ticket_cli.pyandscripts/ticket_memory_plan.py. - [EXTERNAL_DOWNLOADS]: The
run.shscript utilizes theuvpackage manager to synchronize Python dependencies from official public registries based on thepyproject.tomlconfiguration. - [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it processes external GitHub issue content and has high-privilege capabilities.
- Ingestion points: Issue bodies are ingested from GitHub in
scripts/ticket_memory_plan.pyandscripts/ticket_cli.py. - Boundary markers: Machine-readable data is isolated within
<!-- ticket-skill -->HTML comments to distinguish it from untrusted prose. - Capability inventory: The skill can execute arbitrary shell commands via the
verifycommand and perform repository mutations via theghCLI. - Sanitization: There is no sanitization or validation of the shell commands supplied to the
verifycommand.
Audit Metadata