ai-to-spec

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its processing of untrusted data and external write capabilities. * Ingestion points: The skill reads from the 'current conversation context and codebase understanding' (SKILL.md). * Boundary markers: There are no instructions to use delimiters or ignore embedded commands in the source data. * Capability inventory: The skill has the capability to 'publish it to the project issue tracker' (SKILL.md), which involves interacting with external APIs or CLI tools. * Sanitization: No mechanisms are defined to sanitize or validate the synthesized content before it is published externally.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 01:27 PM
Security Audit — agent-trust-hub — ai-to-spec