management-talk
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes technical content from potentially untrusted external sources.
- Ingestion points: The skill consumes technical text provided by the user and fetches data (summary, status, comments) from external Jira tickets via the Jira API.
- Boundary markers: The instructions lack specific requirements for using delimiters or protective wrappers around the input data to prevent the model from executing embedded instructions.
- Capability inventory: The skill has access to tools for reading from and writing to Jira tickets, which could be leveraged if an injection attack successfully manipulates the agent's behavior.
- Sanitization: There are no defined processes for sanitizing, filtering, or validating the technical content before it is processed or reflected in draft updates.
Audit Metadata