to-tickets

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external data which may contain malicious instructions designed to manipulate agent output.
  • Ingestion points: Reads full bodies and comments from spec paths, issue numbers, or URLs (SKILL.md).
  • Boundary markers: Content is fetched and processed without delimiters or instructions to ignore embedded commands.
  • Capability inventory: Performs file writes to the local ".scratch/" directory and publishes issues to external trackers like GitHub or Linear (SKILL.md).
  • Sanitization: No validation or sanitization of the fetched external content is performed.
  • Mitigation: Step 4 ("Quiz the user") mandates a human approval step, ensuring the user reviews all generated tickets before any files are written or issues published.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 10:29 PM
Security Audit — agent-trust-hub — to-tickets