tickets-to-lanes

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources, specifically GitHub tickets and issues, to determine the build backlog, lanes, and handoffs. This untrusted data could contain malicious instructions designed to manipulate the planning or coordination process.
  • Ingestion points: The skill reads ticket bodies, acceptance criteria, and comments from GitHub via tools like read-the-map and standard GitHub API calls.
  • Capability inventory: The skill possesses the ability to create and modify GitHub issues, manage labels, and generate implementation prompts for future sessions.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands within the processed ticket data are documented.
  • Sanitization: The skill lacks explicit sanitization or validation logic for the content extracted from GitHub tickets before using it to structure the lanes and coordination issue.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 12:38 PM
Security Audit — agent-trust-hub — tickets-to-lanes