to-spec
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a structured template and workflow for documentation synthesis. It does not exhibit any malicious patterns, obfuscation, or unauthorized access to sensitive system resources.
- [DATA_EXPOSURE]: The skill manages local documentation files in paths like
work/anddocs/agents/issue-tracker.md. This behavior is consistent with its stated purpose of specification publication and project documentation management. - [COMMAND_EXECUTION]: The skill references internal agent commands (e.g.,
/council,/best-practices-research,/setup-work,/to-tickets) to sequence validation and setup tasks. These are platform-specific instructions for the agent's internal workflow and do not involve arbitrary shell execution or remote code execution. - [PROMPT_INJECTION]: The instructions do not contain any patterns designed to override safety filters or bypass agent constraints. The inclusion of
disable-model-invocation: truein the frontmatter serves as an additional safety restriction on the skill's capabilities.
Audit Metadata