to-spec

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill generates technical specifications based on existing conversation history and codebase content. This creates a surface for indirect prompt injection where malicious instructions embedded in the codebase or previous discussion could influence the generated spec or subsequent agent actions.\n- [INDIRECT_PROMPT_INJECTION] Evidence Chain:\n
  • Ingestion points: Processes 'current conversation context and codebase understanding' (SKILL.md).\n
  • Boundary markers: None provided to separate untrusted data from the synthesis instructions.\n
  • Capability inventory: Includes repo exploration and publishing to an external issue tracker (SKILL.md).\n
  • Sanitization: No validation or filtering of the processed content is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 06:57 AM
Security Audit — agent-trust-hub — to-spec