to-spec
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious behavior, obfuscation, or safety bypasses were identified. The skill acts as a documentation synthesizer using provided templates and does not execute untrusted code or exfiltrate sensitive data.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it processes untrusted data from the repository to generate specifications published to an external tracker. This is the primary purpose of the skill and no specific vulnerabilities were found in the implementation logic.\n
- Ingestion points: Repository files and conversation history (referenced in SKILL.md).\n
- Boundary markers: None present to delimit untrusted codebase content from the generated spec.\n
- Capability inventory: Ability to publish to the project issue tracker and apply labels.\n
- Sanitization: No sanitization or filtering of codebase content is mentioned before publication.
Audit Metadata