to-issues
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Surface for indirect prompt injection detected as the skill processes external, potentially untrusted content to drive agent behavior.
- Ingestion points: Fetches issue bodies and comments from the project tracker and reads from the codebase (SKILL.md).
- Boundary markers: Absent. The skill does not instruct the agent to use delimiters or ignore embedded instructions within the fetched context.
- Capability inventory: The skill possesses the capability to write and publish new issues to the project issue tracker (SKILL.md).
- Sanitization: Absent. No validation or filtering logic is defined for the content retrieved from external sources.
Audit Metadata