to-spec

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from the conversation history and the local repository to generate its output.
  • Ingestion points: The skill synthesizes information from the "current conversation context and codebase understanding".
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore instructions embedded within the codebase or conversation.
  • Capability inventory: The skill reads files from the repository and utilizes tools to publish content to an external issue tracker.
  • Sanitization: No specific data sanitization or filtering steps are defined for the ingested content.
  • Mitigation: The skill includes a mandatory human-in-the-loop checkpoint ("Check with the user that these seams match their expectations") before proceeding to the final publication step.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 10:37 AM
Security Audit — agent-trust-hub — to-spec