to-tickets

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform repository management tasks using the GitHub CLI (gh), including creating issues and posting comments using gh api. It also prescribes the use of pnpm for executing testing and validation commands in the development environment.\n- [DYNAMIC_EXECUTION]: The skill defines a process where the agent generates shell command snippets within ticket verification sections. These commands are intended to be executed by the agent at a later stage to verify the implementation of tasks, representing a dynamic execution pattern.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external and untrusted sources, such as issue tracker bodies, comments, and external specification documents.\n
  • Ingestion points: Data is gathered from issue URLs and descriptions as described in the context gathering step of SKILL.md.\n
  • Boundary markers: The instructions do not specify the use of delimiters or isolation techniques to prevent the agent from following instructions embedded in the external content.\n
  • Capability inventory: The skill has access to shell execution via gh and pnpm, as well as the ability to write to the local file system.\n
  • Sanitization: There are no requirements for sanitizing or validating the content retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 05:41 PM
Security Audit — agent-trust-hub — to-tickets