to-spec

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes recent context and requirements to generate a specification document. This creates an attack surface where instructions embedded in external context could influence the content of the generated specification. However, the scope is limited to writing a local file (.agents/issues/spec.md) and follows standard design documentation workflows.
  • [SAFE]: No malicious patterns, obfuscation, unauthorized network operations, or hardcoded credentials were detected. The skill performs a benign documentation task within the project's agent workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 03:17 AM
Security Audit — agent-trust-hub — to-spec