to-spec

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests conversation context and repository data which are untrusted inputs.
  • Ingestion points: Conversation history and repository exploration (Step 1).
  • Boundary markers: Absent; there are no specific delimiters to distinguish between conversation history and instructions.
  • Capability inventory: Repository read access and potential issue tracker write access via external tools.
  • Sanitization: None described in the prompt logic.
  • [COMMAND_EXECUTION]: The instructions reference internal agent commands (/setup-matt-pocock-skills, /spec-executor, /to-tickets) to manage dependencies and workflow state transitions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 01:22 AM
Security Audit — agent-trust-hub — to-spec