to-issues
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content, such as issue comments, specs, and PRDs, which serves as a potential ingestion point for indirect prompt injection. However, the risk is mitigated by a mandatory 'Quiz the user' step where the agent must present the proposed issue breakdown for human approval before publishing anything to the issue tracker. This workflow ensures that any potentially malicious instructions embedded in the source material are reviewed by a human before being executed as actions.
Audit Metadata