to-spec

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's primary function is synthesis and documentation, which it performs using standard repository exploration. No malicious behaviors such as credential theft, remote code execution, or persistence were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes conversation context and codebase information, creating a surface for potential indirect prompt injection. However, this is an inherent part of its synthesis function and does not represent an active threat.
  • Ingestion points: conversation context and repository contents (SKILL.md).
  • Boundary markers: absent.
  • Capability inventory: repository reading and issue tracker publishing (SKILL.md).
  • Sanitization: absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 11:36 AM
Security Audit — agent-trust-hub — to-spec