skills/moontory/skills/ticket-flow/Gen Agent Trust Hub

ticket-flow

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and follow external data, including 'repository instructions' and the 'orchestrator' skill, which could contain malicious directives.
  • Ingestion points: Processes branch names, repository instructions, project code, and content from referenced skills (SKILL.md).
  • Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions within the ingested repository data.
  • Capability inventory: Performs terminal operations via delegated roles (explore, build, plan, review) and git operations including commits and pull requests.
  • Sanitization: The instructions do not specify any validation or sanitization for instructions found within the repository or external skills.
  • [METADATA_POISONING]: The skill includes an explicit instruction to "Never add co-author, generated-with, or AI attribution text." This directive enforces the removal of metadata that would identify the content as AI-generated, which could be used to circumvent organizational policies or audit logs regarding AI usage.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 04:18 AM
Security Audit — agent-trust-hub — ticket-flow