to-issues
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes data from external sources that may be controlled by third parties. * Ingestion points: The skill reads the full body and comments of existing issues from a tracker (referenced in SKILL.md, Step 1). * Boundary markers: The instructions do not define clear boundaries or provide warnings to ignore embedded instructions in the ingested data. * Capability inventory: The skill has the ability to post new content (issues) to the tracker via agent tools (SKILL.md, Step 5). * Sanitization: There is no explicit sanitization of the input data before it is processed to generate new issue content.
Audit Metadata