ticket

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The verify command in scripts/ticket_cli.py executes shell commands provided as arguments via the --cmd flag. It uses subprocess.run(command, shell=True), allowing for arbitrary local command execution as a method of providing work verification.
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to delegate functionality to established tools including git and gh (GitHub CLI) for repository state management and issue manipulation in scripts/ticket_cli.py and scripts/ticket_memory_plan.py.
  • [EXTERNAL_DOWNLOADS]: The run.sh script utilizes the uv package manager to synchronize Python dependencies from official public registries based on the pyproject.toml configuration.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it processes external GitHub issue content and has high-privilege capabilities.
  • Ingestion points: Issue bodies are ingested from GitHub in scripts/ticket_memory_plan.py and scripts/ticket_cli.py.
  • Boundary markers: Machine-readable data is isolated within <!-- ticket-skill --> HTML comments to distinguish it from untrusted prose.
  • Capability inventory: The skill can execute arbitrary shell commands via the verify command and perform repository mutations via the gh CLI.
  • Sanitization: There is no sanitization or validation of the shell commands supplied to the verify command.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — ticket