to-tickets-plus
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data retrieved from external GitHub issues to perform ticket hardening and plan updates, creating a surface for indirect prompt injection.\n
- Ingestion points: The skill uses
gh issue viewto fetch the contents of Epics and sub-issues (documented in sections 1 and 3 ofSKILL.md).\n - Boundary markers: There are no defined boundary markers or instructions to ignore embedded commands when the agent processes the fetched issue bodies.\n
- Capability inventory: The skill possesses the capability to create, edit, and close GitHub issues via the
ghCLI and can execute local shell commands.\n - Sanitization: The skill does not perform sanitization or validation of the ingested issue content before it is used to populate new issues or the Epic's plan comment.
Audit Metadata