to-spec

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, potentially untrusted data to generate output for external services.
  • Ingestion points: The skill utilizes the 'current conversation context' and 'codebase understanding' as defined in SKILL.md.
  • Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following instructions embedded within the conversation history.
  • Capability inventory: The skill includes instructions to explore the repository and publish generated content to a project issue tracker (SKILL.md).
  • Sanitization: The instructions do not specify any validation, filtering, or escaping of the conversation content before it is processed into the final specification.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 05:44 PM
Security Audit — agent-trust-hub — to-spec