skills/niekcandaele/skills/to-tickets/Gen Agent Trust Hub

to-tickets

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a shell command (ls) to locate TRACKER.md configuration files within the project structure. This is a localized search for configuration discovery and does not involve dangerous arguments or privilege escalation.
  • [EXTERNAL_DOWNLOADS]: The documentation references an external GitHub repository (github.com/mattpocock/skills) for attribution and licensing purposes. This is a reference to a well-known developer and is used purely for documentation.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from external sources, such as issue bodies, comments, and project specifications, to generate ticket content. While this creates a surface for indirect prompt injection, it is central to the skill's primary purpose of summarizing and breaking down tasks, and no evidence of exploitation was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 07:18 AM
Security Audit — agent-trust-hub — to-tickets