refine-issue-plan
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (issue bodies and comments), creating a surface for potential indirect prompt injection.
- Ingestion points: Accesses issue tracker metadata, bodies, comments, and repository context (SKILL.md, Section 1).
- Boundary markers: Implements structured HTML comment tags to separate AI-generated content from existing issue data.
- Capability inventory: Possesses capabilities to modify issue tracker content and metadata (SKILL.md, Section 6).
- Sanitization: Requires explicit user verification and approval for all previews and tracker mutations, serving as a human-in-the-loop control (SKILL.md, Section 5).
Audit Metadata