skills/marcioaltoe/skills/to-tickets/Gen Agent Trust Hub

to-tickets

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's functions are confined to its stated purpose of drafting and publishing project tickets. It does not attempt to access sensitive system files or execute suspicious code.- [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it is designed to read and process data from external URLs and issue trackers.
  • Ingestion points: SKILL.md (Process Step 1) directs the agent to fetch external references and read bodies and comments from issues.
  • Boundary markers: None. The skill does not specify the use of delimiters or 'ignore' instructions for the ingested content.
  • Capability inventory: The skill can perform local file writes in the .scratch/ directory and publish to external issue trackers.
  • Sanitization: None. The skill does not instruct the agent to sanitize or validate external content before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 04:54 PM
Security Audit — agent-trust-hub — to-tickets