to-spec
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's behavior is consistent with its stated purpose of automating project documentation and issue tracking. No evidence of malicious logic, credential harvesting, or unauthorized remote code execution was found.
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it ingests untrusted data from conversation history and the repository codebase to generate its output. This is a functional requirement and is documented below according to safety protocols.
- Ingestion points: Conversation context and codebase files (SKILL.md).
- Boundary markers: Absent from instructions.
- Capability inventory: Writing and publishing issues to an external issue tracker (SKILL.md).
- Sanitization: No explicit validation or filtering of the source context is described.
Audit Metadata