skills/eszxcvfd/skills/to-spec/Gen Agent Trust Hub

to-spec

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill follows a standard workflow for creating technical documentation based on project context. \n- [DATA_EXFILTRATION]: The skill publishes content to an external issue tracker. This behavior is intended for the purpose of specification management and is explicitly described in the skill documentation. \n- [PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection by processing conversation and repository data. \n
  • Ingestion points: Reads from the current conversation context and performs repository exploration to understand the codebase. \n
  • Boundary markers: Absent. There are no instructions provided to the agent to treat external data as untrusted or to ignore embedded instructions. \n
  • Capability inventory: The skill has the ability to explore the file system and publish content to an external issue tracker. \n
  • Sanitization: Absent. The skill relies on the agent's synthesis logic to format the output template without explicit content filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 01:31 AM
Security Audit — agent-trust-hub — to-spec