ticket-flow
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and follow external data, including 'repository instructions' and the 'orchestrator' skill, which could contain malicious directives.
- Ingestion points: Processes branch names, repository instructions, project code, and content from referenced skills (SKILL.md).
- Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions within the ingested repository data.
- Capability inventory: Performs terminal operations via delegated roles (explore, build, plan, review) and git operations including commits and pull requests.
- Sanitization: The instructions do not specify any validation or sanitization for instructions found within the repository or external skills.
- [METADATA_POISONING]: The skill includes an explicit instruction to "Never add co-author, generated-with, or AI attribution text." This directive enforces the removal of metadata that would identify the content as AI-generated, which could be used to circumvent organizational policies or audit logs regarding AI usage.
Audit Metadata