to-issues

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to ingest and process external data such as PRDs, plans, and feature descriptions (SKILL.md).
  • Ingestion points: Processes user-provided or external project documentation as the primary input for generating task breakdowns.
  • Boundary markers: The skill lacks instructions for the agent to use delimiters or to ignore potential instructions embedded within the processed documentation.
  • Capability inventory: The issue template requires the agent to generate 'verification commands', which could be manipulated if the source material contains malicious command snippets.
  • Sanitization: There are no instructions provided to validate or sanitize the content extracted from the source plans before it is formatted into issues or commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:50 AM
Security Audit — agent-trust-hub — to-issues