decisions-to-specs
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from GitHub issue bodies and resolution comments to generate repository files.
- Ingestion points: Step 1 involves reading the 'Destination' and 'Decisions so far' sections of a wayfinder map issue in SKILL.md, as well as resolution comments from child tickets.
- Boundary markers: No explicit delimiters or instructions are provided to the agent to treat this data as untrusted or to ignore embedded instructions.
- Capability inventory: The skill possesses significant capabilities, including writing to the repository (Step 5), executing Git commands (Step 4), and updating GitHub issue metadata (Step 8 and 9).
- Sanitization: There are no instructions for sanitizing or escaping the data retrieved from GitHub before it is used in file writing or issue updates.
- [COMMAND_EXECUTION]: The skill relies on shell commands for Git operations, specifically incorporating a user-provided map number into branch names and worktree paths.
- Evidence: The instructions in Step 4 specify commands like 'git worktree add -b docs/specs- origin/main', where '' is derived from the user argument. This presents a potential surface for command injection if the argument is not properly validated before execution.
Audit Metadata