to-spec

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and configuration files do not contain any malicious patterns, obfuscation, or unauthorized data access operations.- [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it synthesizes untrusted data from the conversation and codebase to publish to an issue tracker. However, no specific exploitable patterns were identified.
  • Ingestion points: Current conversation context and codebase exploration (SKILL.md)
  • Boundary markers: None present
  • Capability inventory: Publication of documentation to the project issue tracker
  • Sanitization: No explicit sanitization or content filtering is defined
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 10:29 PM
Security Audit — agent-trust-hub — to-spec