to-spec
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill generates technical specifications based on existing conversation history and codebase content. This creates a surface for indirect prompt injection where malicious instructions embedded in the codebase or previous discussion could influence the generated spec or subsequent agent actions.\n- [INDIRECT_PROMPT_INJECTION] Evidence Chain:\n
- Ingestion points: Processes 'current conversation context and codebase understanding' (SKILL.md).\n
- Boundary markers: None provided to separate untrusted data from the synthesis instructions.\n
- Capability inventory: Includes repo exploration and publishing to an external issue tracker (SKILL.md).\n
- Sanitization: No validation or filtering of the processed content is specified.
Audit Metadata