to-spec

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from the conversation context and repository files to produce output that is published to an external issue tracker.
  • Ingestion points: Current conversation context and codebase understanding (SKILL.md).
  • Boundary markers: Absent. The instructions do not specify delimiters or provide guidance for the model to distinguish between its own instructions and content found within the context or files.
  • Capability inventory: Repository exploration (read) and publishing to a project issue tracker (write).
  • Sanitization: No sanitization or validation logic is defined to check the content of the conversation or codebase before it is synthesized into a specification.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 10:27 AM
Security Audit — agent-trust-hub — to-spec