to-issues

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows a legitimate workflow for project management, specifically breaking down plans into tracker issues using vertical slices. It includes safety limitations that prevent destructive or external-message actions without explicit user approval.
  • [DATA_INGESTION]: The skill processes data from external issue trackers, including body text and comments. While this presents an indirect prompt injection surface common to all integration tools, the workflow mandates an iteration phase where the user must review and approve all proposed issues before they are published, providing a strong control against accidental obedience to instructions embedded in external data.
  • [COMMAND_EXECUTION]: The skill uses tools like claude-code and cursor to explore the codebase and manage issues. These operations are scoped to the user's project environment and are performed as part of the primary skill functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 05:10 PM
Security Audit — agent-trust-hub — to-issues