to-spec

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the repository and conversation context and uses it to perform a write operation to an external system.
  • Ingestion points: The skill instructions direct the agent to explore the repository codebase and synthesize the current conversation context (SKILL.md).
  • Capability inventory: The agent has the capability to publish synthesized content to a project issue tracker (SKILL.md).
  • Boundary markers: No specific delimiters or instructions are provided to help the agent distinguish between its instructions and potentially malicious content within the repository or chat history.
  • Sanitization: There are no explicit instructions for sanitizing or validating the content extracted from the repository before it is published to the issue tracker.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 01:41 PM
Security Audit — agent-trust-hub — to-spec