pm-monitor-ticket-triage
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) because it processes untrusted data from external sources. * Ingestion points: Untrusted data enters the agent context via intake items such as ticket exports, comments, and client feedback described in Step 1 and Step 4 of SKILL.md. * Boundary markers: The instructions do not provide delimiters or specific warnings to ignore embedded instructions within the processed data. * Capability inventory: The skill directs the agent to draft responses and route tasks based on intake, which could be exploited if the agent has active tool access (e.g., Jira or Slack APIs). * Sanitization: No validation or sanitization steps are defined for the external content before processing.
Audit Metadata