to-issues

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructional content for managing a project workflow. No attempts to bypass safety filters, override system instructions, or use adversarial role-play patterns were identified.
  • [DATA_EXFILTRATION]: The skill describes processes for reading and writing data to an issue tracker. The limitations section correctly identifies that destructive or production actions require explicit user approval, and no unauthorized network exfiltration patterns were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external sources, which constitutes a vulnerability surface for indirect prompt injection. 1. Ingestion points: The skill reads issue bodies, comments, and planning documents (plans, specs, PRDs) from the issue tracker or project context. 2. Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the ingested content. 3. Capability inventory: The workflow requires exploring the codebase and publishing new issues to a project tracker. 4. Sanitization: There are no explicit requirements for sanitizing or validating the content retrieved from external sources before it is processed or published.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 12:50 AM
Security Audit — agent-trust-hub — to-issues