to-tickets
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection through its ingestion of external data sources.
- Ingestion points: Step 1 and Step 2 of the process describe fetching and reading the full body and comments of external specifications, issue URLs, and exploring the local codebase.
- Boundary markers: The instructions do not define delimiters or provide specific guidance to the agent to ignore instructions that might be embedded within the external content it retrieves.
- Capability inventory: The agent has permissions to write files to the local
.scratch/directory and interact with external project management platforms such as GitHub and Linear to create new issues. - Sanitization: There are no requirements in the skill's instructions for the agent to sanitize or validate the external data before processing it to generate ticket content.
Audit Metadata