to-spec
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill takes the current conversation context and codebase understanding as input to produce a technical specification.
- Ingestion points: The skill processes data from the conversation history and repository files (referenced in SKILL.md under the 'Process' section).
- Boundary markers: Absent; there are no instructions to delimit external data or ignore embedded instructions within files.
- Capability inventory: The skill utilizes repository exploration tools and issue tracker publishing capabilities (implied by the instruction to 'publish it to the project issue tracker').
- Sanitization: Absent; the skill does not specify any validation or sanitization of synthesized content before it is published externally.
- [COMMAND_EXECUTION]: The skill instructs the agent to explore the repository and publish to an issue tracker. These actions are performed using the agent's available CLI or API tools based on the instructions in SKILL.md. This is typical functionality for a developer-oriented skill and does not include malicious command patterns.
Audit Metadata