plan-tickets

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts user-provided plan descriptions to generate ticket drafts.
  • Ingestion points: The skill ingests "Plan input" text from users as described in SKILL.md and EXAMPLES.md.
  • Boundary markers: No explicit delimiters are specified for the input text, though the output follows a strict five-section Markdown structure.
  • Capability inventory: The skill is capable of performing write operations to external tracker APIs (Jira, Linear, GitHub Issues) as defined in SKILL.md.
  • Sanitization: The skill relies on a mandatory human-in-the-loop review process (draft-only default) and explicit user approval before any API interaction occurs, effectively mitigating the risk of automated injection attacks.
  • [SAFE]: The skill includes explicit security gates that prevent the assumption of credentials or project settings, requiring that these be managed securely outside the repository environment.
  • [SAFE]: A "HARD-GATE" policy is enforced in SKILL.md to prevent the agent from creating issues autonomously, ensuring all external actions are user-initiated.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 09:25 PM
Security Audit — agent-trust-hub — plan-tickets