skills/mtgvim/tiger-kit/tk-to-tickets/Gen Agent Trust Hub

tk-to-tickets

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external file data from spec.md, which is an ingestion point for untrusted content. It mitigates indirect injection risks through mandatory status verification ('Ready' check), lineage matching, and an 'approval boundary' constraint on its output. The potential for the agent to follow hidden instructions in the source file is minimized by the skill's restriction to a specific Markdown output format.
  • [DATA_EXFILTRATION]: The skill is constrained to reading and writing files within the /home/tigeryoo/workspace/tiger-kit/.tigerkit/ directory. It explicitly prohibits remote operations, issue creation, or any output outside the defined local workspace, preventing data exfiltration to external systems.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 12:10 AM
Security Audit — agent-trust-hub — tk-to-tickets