tickets-to-lanes
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources, specifically GitHub tickets and issues, to determine the build backlog, lanes, and handoffs. This untrusted data could contain malicious instructions designed to manipulate the planning or coordination process.
- Ingestion points: The skill reads ticket bodies, acceptance criteria, and comments from GitHub via tools like
read-the-mapand standard GitHub API calls. - Capability inventory: The skill possesses the ability to create and modify GitHub issues, manage labels, and generate implementation prompts for future sessions.
- Boundary markers: No specific delimiters or instructions to ignore embedded commands within the processed ticket data are documented.
- Sanitization: The skill lacks explicit sanitization or validation logic for the content extracted from GitHub tickets before using it to structure the lanes and coordination issue.
Audit Metadata