ticket-triage

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted customer messages and issue descriptions which may contain hidden or explicit instructions intended to manipulate the triage process (e.g., forcing a 'Critical' priority or specific routing).
  • Ingestion points: The /ticket-triage command accepts arbitrary text input as shown in the usage examples in SKILL.md.
  • Boundary markers: The instructions do not define delimiters or specific 'ignore instructions' guards when processing the input variables.
  • Capability inventory: The skill is capable of external searches and reading content via tavily_search and context_dev_scrape_markdown (referenced in references/sandbase-api-map.md). While these are read-only, manipulated triage results could lead to downstream misconfiguration or improper resource allocation.
  • Sanitization: No sanitization or validation of the input text is mentioned to filter out potential injection patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:10 AM
Security Audit — agent-trust-hub — ticket-triage