skills/carnaverone/skills/to-spec/Gen Agent Trust Hub

to-spec

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it synthesizes external, potentially untrusted data into an output that is then published to an external system.
  • Ingestion points: The skill ingests the current conversation history and codebase content (SKILL.md).
  • Boundary markers: The skill does not employ explicit delimiters or instructions to differentiate between its own logic and the data gathered from the conversation or repo.
  • Capability inventory: The skill utilizes the agent's ability to read repository files and publish to a project issue tracker.
  • Sanitization: There are no explicit sanitization or validation mechanisms defined to filter malicious instructions that might be contained within the conversation history or code before publication to the issue tracker.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:09 PM
Security Audit — agent-trust-hub — to-spec