skills/fdarkaou/agent-skills/to-spec/Gen Agent Trust Hub

to-spec

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's behavior is consistent with its stated purpose of automating project documentation and issue tracking. No evidence of malicious logic, credential harvesting, or unauthorized remote code execution was found.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it ingests untrusted data from conversation history and the repository codebase to generate its output. This is a functional requirement and is documented below according to safety protocols.
  • Ingestion points: Conversation context and codebase files (SKILL.md).
  • Boundary markers: Absent from instructions.
  • Capability inventory: Writing and publishing issues to an external issue tracker (SKILL.md).
  • Sanitization: No explicit validation or filtering of the source context is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 10:40 AM
Security Audit — agent-trust-hub — to-spec