pm-ticketing-integration

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill employs highly authoritative language such as 'CRITICAL ENFORCEMENT' and 'MUST NEVER' to override the agent's default tool selection and behavior. It also implements a 'Violation Prevention' section that describes a simulated session monitoring and escalation system ('Violation #2: ESCALATION
  • Session flagged for review') intended to coerce agent compliance with the protocol.
  • [PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by instructing the agent to extract and interpolate untrusted external data into task contexts for other agents.
  • Ingestion points: Ticket IDs, issue URLs, and ticket summaries provided by the user or the external ticketing agent as described in SKILL.md.
  • Boundary markers: Absent. The protocol interpolates variables like {ticket_id}, {summary_from_ticketing_agent}, and {task_description} directly into prompts without the use of delimiters or 'ignore' instructions to prevent the agent from obeying instructions embedded within the ticket data.
  • Capability inventory: The skill orchestrates a multi-agent workflow involving 'ticketing', 'research', 'engineer', and 'QA' agents, which collectively possess capabilities for file modification, code implementation, and network interaction.
  • Sanitization: Absent. The instructions do not specify any validation, escaping, or filtering processes for the data retrieved from tickets before it is passed to other agents in the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 02:30 PM
Security Audit — agent-trust-hub — pm-ticketing-integration