create-github-issues-for-unmet-specification-requirements

Pass

Audited by Gen Agent Trust Hub on Feb 25, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill consists exclusively of markdown-based instructions for the agent's workflow. No scripts, configuration files, or binaries are included.
  • [PROMPT_INJECTION]: The skill processes untrusted external content (specification files), creating a surface for indirect prompt injection. 1. Ingestion points: Data is read from the user-specified ${file} and the /spec/ directory. 2. Boundary markers: No delimiters or markers are defined to isolate external data from the agent's instructions. 3. Capability inventory: The agent is instructed to use search_issues and create_issue tools. 4. Sanitization: No explicit content validation or sanitization process is described in the skill workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 25, 2026, 05:25 AM