to-tickets
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's logic is transparent and task-oriented, focusing on project management workflows without introducing malicious patterns.
- [DATA_EXFILTRATION]: The skill interacts with well-known services (GitHub, Linear) and local files to manage project tasks, which is consistent with its primary purpose and stated configuration.
- [PROMPT_INJECTION]: While the skill ingests data from external sources like URLs or issue comments, it implements a mandatory human-in-the-loop step ('Quiz the user') that requires explicit user approval of the proposed ticket breakdown before any publishing or file-writing occurs, effectively mitigating the risk of indirect prompt injection.
Audit Metadata