plan-tickets
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill accepts user-provided plan descriptions to generate ticket drafts.
- Ingestion points: The skill ingests "Plan input" text from users as described in
SKILL.mdandEXAMPLES.md. - Boundary markers: No explicit delimiters are specified for the input text, though the output follows a strict five-section Markdown structure.
- Capability inventory: The skill is capable of performing write operations to external tracker APIs (Jira, Linear, GitHub Issues) as defined in
SKILL.md. - Sanitization: The skill relies on a mandatory human-in-the-loop review process (draft-only default) and explicit user approval before any API interaction occurs, effectively mitigating the risk of automated injection attacks.
- [SAFE]: The skill includes explicit security gates that prevent the assumption of credentials or project settings, requiring that these be managed securely outside the repository environment.
- [SAFE]: A "HARD-GATE" policy is enforced in
SKILL.mdto prevent the agent from creating issues autonomously, ensuring all external actions are user-initiated.
Audit Metadata