refine-issue-plan

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (issue bodies and comments), creating a surface for potential indirect prompt injection.
  • Ingestion points: Accesses issue tracker metadata, bodies, comments, and repository context (SKILL.md, Section 1).
  • Boundary markers: Implements structured HTML comment tags to separate AI-generated content from existing issue data.
  • Capability inventory: Possesses capabilities to modify issue tracker content and metadata (SKILL.md, Section 6).
  • Sanitization: Requires explicit user verification and approval for all previews and tracker mutations, serving as a human-in-the-loop control (SKILL.md, Section 5).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 08:56 AM
Security Audit — agent-trust-hub — refine-issue-plan