to-spec

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a structured template and workflow for documentation synthesis. It does not exhibit any malicious patterns, obfuscation, or unauthorized access to sensitive system resources.
  • [DATA_EXPOSURE]: The skill manages local documentation files in paths like work/ and docs/agents/issue-tracker.md. This behavior is consistent with its stated purpose of specification publication and project documentation management.
  • [COMMAND_EXECUTION]: The skill references internal agent commands (e.g., /council, /best-practices-research, /setup-work, /to-tickets) to sequence validation and setup tasks. These are platform-specific instructions for the agent's internal workflow and do not involve arbitrary shell execution or remote code execution.
  • [PROMPT_INJECTION]: The instructions do not contain any patterns designed to override safety filters or bypass agent constraints. The inclusion of disable-model-invocation: true in the frontmatter serves as an additional safety restriction on the skill's capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 11:45 AM
Security Audit — agent-trust-hub — to-spec