to-tickets
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes external files to generate tickets.
- Ingestion points: Reads user-provided specifications, conversation history, and the existing repository codebase.
- Boundary markers: The instructions do not define specific delimiters for external content within the generated output.
- Capability inventory: The skill can write markdown files to the local file system (docs/tickets/) and interact with the GitHub API to create issues.
- Sanitization: No specific sanitization methods are mentioned, though a mandatory human-in-the-loop approval step is required.
- [SAFE]: No signs of malicious behavior, data exfiltration, obfuscation, or unauthorized command execution were found. The skill is purely instructional and emphasizes user verification.
Audit Metadata