decisions-to-specs

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from GitHub issue bodies and resolution comments to generate repository files.
  • Ingestion points: Step 1 involves reading the 'Destination' and 'Decisions so far' sections of a wayfinder map issue in SKILL.md, as well as resolution comments from child tickets.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat this data as untrusted or to ignore embedded instructions.
  • Capability inventory: The skill possesses significant capabilities, including writing to the repository (Step 5), executing Git commands (Step 4), and updating GitHub issue metadata (Step 8 and 9).
  • Sanitization: There are no instructions for sanitizing or escaping the data retrieved from GitHub before it is used in file writing or issue updates.
  • [COMMAND_EXECUTION]: The skill relies on shell commands for Git operations, specifically incorporating a user-provided map number into branch names and worktree paths.
  • Evidence: The instructions in Step 4 specify commands like 'git worktree add -b docs/specs- origin/main', where '' is derived from the user argument. This presents a potential surface for command injection if the argument is not properly validated before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 10:35 PM
Security Audit — agent-trust-hub — decisions-to-specs