to-tickets
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's functions are confined to its stated purpose of drafting and publishing project tickets. It does not attempt to access sensitive system files or execute suspicious code.- [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it is designed to read and process data from external URLs and issue trackers.
- Ingestion points: SKILL.md (Process Step 1) directs the agent to fetch external references and read bodies and comments from issues.
- Boundary markers: None. The skill does not specify the use of delimiters or 'ignore' instructions for the ingested content.
- Capability inventory: The skill can perform local file writes in the
.scratch/directory and publish to external issue trackers. - Sanitization: None. The skill does not instruct the agent to sanitize or validate external content before processing it.
Audit Metadata