plan
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to ingest and process external, untrusted data from tickets and product context, creating a surface for potential instruction injection.
- Ingestion points: External tickets, product context, and the AGENTS.md file referenced in the Process section.
- Boundary markers: The skill does not provide instructions for using boundary markers or explicitly ignoring commands found within the ingested data.
- Capability inventory: The skill generates markdown plans that act as direct instructions for subsequent implementation and execution tasks.
- Sanitization: No validation or sanitization process is defined for the content retrieved from external sources before it influences the plan generation.
Audit Metadata