to-spec
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes conversation context and repository content to generate output for an external issue tracker, creating an attack surface for indirect prompt injection.
- Ingestion points: Reads conversation context and repository files (SKILL.md).
- Boundary markers: Instructions do not specify delimiters or warnings to distinguish between user-provided data and system instructions.
- Capability inventory: The agent can read codebase files and publish content to an issue tracker.
- Sanitization: The skill lacks instructions for sanitizing or validating the synthesized content before transmission to the external tracker.
Audit Metadata