to-spec
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes conversation context and codebase information to generate and publish specifications.
- Ingestion points: The agent reads the current conversation context and explores the repository to gather context as described in the process section of SKILL.md.
- Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the untrusted conversation or code context.
- Capability inventory: The skill instructs the agent to explore the repo (read) and publish synthesized content to an external project issue tracker (network write).
- Sanitization: There are no explicit instructions or automated filters for the agent to sanitize or escape the ingested data before formatting it into the spec template or publishing it.
Audit Metadata