to-issues
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is subject to indirect prompt injection because it ingests data from external plans and issues to generate new content.
- Ingestion points: PRDs, specifications, and fetched issue content (SKILL.md, Step 1).
- Boundary markers: Absent; no instructions are provided to the agent to distinguish between task data and embedded commands.
- Capability inventory: Reading codebase files and issue tracker content; writing/publishing new issues to the tracker.
- Sanitization: Absent; input from source documents is used directly.
- Mitigation: The skill mandates a 'Quiz the user' interaction in Step 4, ensuring all proposed tasks are reviewed and approved by a human before any write operations occur.
Audit Metadata