skills/rca32/skills/to-tickets/Gen Agent Trust Hub

to-tickets

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructions in SKILL.md define a critical sanitization gate that requires the agent to inspect all input sources for credentials, tokens, or private data before decomposition. The agent is explicitly instructed to halt and request a sanitized version if secrets are found, preventing accidental exposure in public issue trackers.
  • [COMMAND_EXECUTION]: The test script scripts/test_source_fingerprint.py utilizes subprocess.run to verify the functionality of the fingerprinting CLI. This implementation is safe as it restricts the command to the current Python interpreter and a fixed local script path, precluding arbitrary command injection.
  • [PROMPT_INJECTION]: The skill is designed to process untrusted natural language specifications, which serves as a potential surface for indirect prompt injection. However, the instructions provide strong mitigations through strict validation checks, requirement mapping, and a multi-phase publication workflow that ensures the agent remains focused on the authorized decomposition task.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 03:26 AM
Security Audit — agent-trust-hub — to-tickets