skills/noelrohi/skills/to-tickets/Gen Agent Trust Hub

to-tickets

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is configured to ingest and process data from external sources that are not under the direct control of the system, creating a surface for indirect prompt injection.
  • Ingestion points: The agent is instructed to fetch and read the full body and comments of external references provided by the user, such as specification files, issue numbers, or URLs (SKILL.md, Step 1).
  • Boundary markers: There are no instructions provided to the agent to use delimiters or specific warnings to ignore instructions that may be embedded within the external content being processed.
  • Capability inventory: The skill has the capability to write local files to the .scratch/ directory and interact with external issue trackers like GitHub and Linear (SKILL.md, Step 5).
  • Sanitization: The skill lacks explicit guidelines for sanitizing or validating the content retrieved from external references before it is used to generate new tickets or documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 05:01 PM
Security Audit — agent-trust-hub — to-tickets