to-spec
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection as it ingests untrusted data and has significant system capabilities.
- Ingestion points: The skill processes the full conversation history and codebase content discovered via
Read,Grep, andGlob(SKILL.md). - Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore or isolate embedded instructions within the ingested data.
- Capability inventory: The agent is granted
Bash,Write, andEdittools, allowing for shell execution and modification of the codebase based on the synthesized spec. - Sanitization: No sanitization, filtering, or validation steps are defined for the data before it is synthesized into a specification or published to an issue tracker.
- [COMMAND_EXECUTION]: The skill is configured with
Bashaccess in theallowed-toolsmetadata, which allows for the execution of arbitrary shell commands within the agent's environment. - [DYNAMIC_EXECUTION]: The skill references a local validator script (
.agent-skills/skill-standardization/scripts/validate_skill.sh), which constitutes the dynamic execution of project-local script files.
Audit Metadata