ticket-triage
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted customer messages and issue descriptions which may contain hidden or explicit instructions intended to manipulate the triage process (e.g., forcing a 'Critical' priority or specific routing).
- Ingestion points: The
/ticket-triagecommand accepts arbitrary text input as shown in the usage examples inSKILL.md. - Boundary markers: The instructions do not define delimiters or specific 'ignore instructions' guards when processing the input variables.
- Capability inventory: The skill is capable of external searches and reading content via
tavily_searchandcontext_dev_scrape_markdown(referenced inreferences/sandbase-api-map.md). While these are read-only, manipulated triage results could lead to downstream misconfiguration or improper resource allocation. - Sanitization: No sanitization or validation of the input text is mentioned to filter out potential injection patterns.
Audit Metadata