to-tickets
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to influence the agent's behavior during ticket generation.
- Ingestion points: The skill fetches and reads full bodies and comments from external issue numbers, URLs, and spec paths (SKILL.md, Step 1).
- Boundary markers: There are no explicit instructions or delimiters used to separate untrusted content from the system instructions or to warn the agent to ignore embedded commands within the fetched data.
- Capability inventory: The agent has the ability to write files to the local .scratch/ directory and perform network operations to publish content to external trackers like GitHub and Linear (SKILL.md, Step 6).
- Sanitization: The skill lacks explicit sanitization or filtering logic for the ingested external content.
- Mitigation: The process includes a mandatory step (Step 5) where the user must review and approve the proposed ticket breakdown before any publication occurs, providing a critical human-in-the-loop check.
Audit Metadata