to-spec
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: Analysis of the skill instructions and configuration reveals no malicious patterns, unauthorized command execution, or hidden network operations. The skill follows a structured template to perform its stated purpose of specification generation and publishing.\n- [PROMPT_INJECTION]: The skill includes an indirect prompt injection surface inherent to its function of processing untrusted data:\n
- Ingestion points: The skill reads the current conversation context and explores the repository codebase for synthesis.\n
- Boundary markers: No explicit markers or instructions are provided to the agent to ignore potentially malicious commands embedded in the conversation or codebase.\n
- Capability inventory: The skill directs the agent to publish the generated output to an external project issue tracker.\n
- Sanitization: The skill does not implement specific input sanitization, relying on the underlying model's safety guardrails and the structured nature of the template.
Audit Metadata