to-issues
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructional content for managing a project workflow. No attempts to bypass safety filters, override system instructions, or use adversarial role-play patterns were identified.
- [DATA_EXFILTRATION]: The skill describes processes for reading and writing data to an issue tracker. The limitations section correctly identifies that destructive or production actions require explicit user approval, and no unauthorized network exfiltration patterns were found.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external sources, which constitutes a vulnerability surface for indirect prompt injection. 1. Ingestion points: The skill reads issue bodies, comments, and planning documents (plans, specs, PRDs) from the issue tracker or project context. 2. Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the ingested content. 3. Capability inventory: The workflow requires exploring the codebase and publishing new issues to a project tracker. 4. Sanitization: There are no explicit requirements for sanitizing or validating the content retrieved from external sources before it is processed or published.
Audit Metadata