backend-dotnet-tickets
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes specification documents which may contain untrusted data from external sources.
- Ingestion points: The agent reads a
spec.mdfile (referenced in theEntregasection) to identify domain rules, invariants, and contracts. - Boundary markers: The instructions lack explicit delimiters or "ignore embedded instructions" warnings for the data being processed.
- Capability inventory: The skill uses the agent's ability to create and write multiple markdown files to the local filesystem at paths like
specs/<slug>/tickets/<NN>-<titulo>.md. - Sanitization: There are no documented steps for sanitizing or validating the content extracted from the specification before it is written to the new ticket files.
Audit Metadata