specs-to-tickets
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from GitHub issues and project documentation which could contain adversarial content. * Ingestion points: Reads wayfinder map issue content and docs/agents/issue-tracker.md. * Capability inventory: Invokes the /to-tickets skill and executes gh api commands to modify repository state. * Boundary markers: Identifies data using specific markdown headers like ## Specs settled. * Sanitization: No explicit sanitization of the retrieved issue text is documented.
- [COMMAND_EXECUTION]: The skill uses the GitHub CLI (gh) to interact with the repository API. * Evidence: Provides specific gh api command templates for managing sub-issues and querying issue database IDs.
Audit Metadata