pm-ticketing-integration
Pass
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill employs highly authoritative language such as 'CRITICAL ENFORCEMENT' and 'MUST NEVER' to override the agent's default tool selection and behavior. It also implements a 'Violation Prevention' section that describes a simulated session monitoring and escalation system ('Violation #2: ESCALATION
- Session flagged for review') intended to coerce agent compliance with the protocol.
- [PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by instructing the agent to extract and interpolate untrusted external data into task contexts for other agents.
- Ingestion points: Ticket IDs, issue URLs, and ticket summaries provided by the user or the external ticketing agent as described in SKILL.md.
- Boundary markers: Absent. The protocol interpolates variables like {ticket_id}, {summary_from_ticketing_agent}, and {task_description} directly into prompts without the use of delimiters or 'ignore' instructions to prevent the agent from obeying instructions embedded within the ticket data.
- Capability inventory: The skill orchestrates a multi-agent workflow involving 'ticketing', 'research', 'engineer', and 'QA' agents, which collectively possess capabilities for file modification, code implementation, and network interaction.
- Sanitization: Absent. The instructions do not specify any validation, escaping, or filtering processes for the data retrieved from tickets before it is passed to other agents in the workflow.
Audit Metadata