to-spec

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the conversation history and the repository codebase to generate project specifications.
  • Ingestion points: Reads current conversation context and performs repository exploration to understand the codebase state.
  • Boundary markers: Absent. The skill does not define specific delimiters or instructions to ignore embedded commands within the processed data.
  • Capability inventory: The skill explores the repository (read access) and publishes synthesized content to a project issue tracker (write access).
  • Sanitization: There are no explicit sanitization or validation steps mentioned for the content synthesized from external inputs before it is published to the issue tracker.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:22 PM
Security Audit — agent-trust-hub — to-spec