to-spec
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes recent context and requirements to generate a specification document. This creates an attack surface where instructions embedded in external context could influence the content of the generated specification. However, the scope is limited to writing a local file (
.agents/issues/spec.md) and follows standard design documentation workflows. - [SAFE]: No malicious patterns, obfuscation, unauthorized network operations, or hardcoded credentials were detected. The skill performs a benign documentation task within the project's agent workspace.
Audit Metadata