to-spec
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests conversation context and repository data which are untrusted inputs.
- Ingestion points: Conversation history and repository exploration (Step 1).
- Boundary markers: Absent; there are no specific delimiters to distinguish between conversation history and instructions.
- Capability inventory: Repository read access and potential issue tracker write access via external tools.
- Sanitization: None described in the prompt logic.
- [COMMAND_EXECUTION]: The instructions reference internal agent commands (
/setup-matt-pocock-skills,/spec-executor,/to-tickets) to manage dependencies and workflow state transitions.
Audit Metadata