to-issues

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources which could be used to influence the agent's behavior or output.
  • Ingestion points: The skill fetches the full body and comments of issues from a project tracker and reads plans, specs, or PRDs provided in the conversation context (SKILL.md, Step 1).
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate the fetched external content or to instruct the agent to ignore any embedded commands within that content.
  • Capability inventory: The skill has the capability to publish new issues to a project issue tracker (SKILL.md, Step 5).
  • Sanitization: The instructions do not specify any validation, filtering, or escaping of the content retrieved from external documents or issue comments before it is used to draft and publish new issues.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 02:12 AM
Security Audit — agent-trust-hub — to-issues