to-spec
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs its primary function of creating technical specifications based on conversation context without any detected malicious patterns or unauthorized behaviors.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill accesses the codebase and publishes to an issue tracker as part of its core functionality. These operations are aligned with its stated purpose and do not target untrusted destinations.
- [INDIRECT_PROMPT_INJECTION]: The skill processes conversation history, which is an ingestion point for untrusted data. Ingestion points: current conversation context. Boundary markers: absent. Capability inventory: repo exploration (read) and issue tracker publishing (write). Sanitization: absent. The risk is mitigated by a human-in-the-loop requirement where the agent must 'Check with the user that these seams match their expectations' before finalizing the specification.
Audit Metadata