to-spec
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by processing untrusted data from conversation context and repository contents to generate output for an external service.
- Ingestion points: Processes conversation history and repository files (SKILL.md).
- Boundary markers: No specific delimiters or instructions are provided to the agent to ignore potentially malicious commands embedded in the processed text.
- Capability inventory: Includes the ability to read the local repository and write to an external project issue tracker.
- Sanitization: No evidence of input validation or sanitization before data is interpolated into the specification template.
Audit Metadata