to-spec

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes conversation context and codebase information to generate and publish specifications.
  • Ingestion points: The agent reads the current conversation context and explores the repository to gather context as described in the process section of SKILL.md.
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the untrusted conversation or code context.
  • Capability inventory: The skill instructs the agent to explore the repo (read) and publish synthesized content to an external project issue tracker (network write).
  • Sanitization: There are no explicit instructions or automated filters for the agent to sanitize or escape the ingested data before formatting it into the spec template or publishing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:01 PM
Security Audit — agent-trust-hub — to-spec