skills/hk-hub/agentskills/to-spec/Gen Agent Trust Hub

to-spec

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill uses a transparent, template-based process for generating specifications and does not exhibit any obfuscation, base64 encoding, or hidden command patterns.
  • [SAFE]: No hardcoded credentials, sensitive file paths (e.g., .ssh, .env), or unauthorized network operations were detected in the skill's definition or referenced setup command.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its data processing and publishing workflow.
  • Ingestion points: The skill reads the current conversation context and performs an exploration of the project's codebase to gather information (SKILL.md).
  • Boundary markers: Absent. The instructions do not specify delimiters or provide warnings to the agent to ignore instructions that might be embedded within the project files or conversation history.
  • Capability inventory: The skill has the capability to publish the synthesized results to the project issue tracker and apply triage labels.
  • Sanitization: Absent. There is no logic or instruction provided to sanitize, filter, or escape the content ingested from the codebase or conversation before it is published to the issue tracker.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — to-spec