ticket-to-code-change

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources that are not fully under the agent's control.
  • Ingestion points: The skill fetches implementation-ready tickets from Jira Cloud or Linear (as described in SKILL.md).
  • Boundary markers: The instructions in SKILL.md (Step 4) for building the prompt do not specify the use of delimiters or explicit instructions for the agent to ignore potentially malicious commands embedded within the ticket description or acceptance criteria.
  • Capability inventory: The resulting automation has significant capabilities, including starting OpenHands conversations to implement code, executing the repository's test suite, and opening pull or merge requests on GitHub, GitLab, or Bitbucket (SKILL.md).
  • Sanitization: No explicit sanitization, filtering, or validation of the ticket content is mentioned before it is interpolated into the agent's prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:36 PM
Security Audit — agent-trust-hub — ticket-to-code-change