spec-miner
Warn
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill is configured to locate and read sensitive environment and configuration files.
- Evidence:
Glob: **/.env*andGrep('os\\.environ|config\\[|settings\\.', include='*.py')found inSKILL.mdandreferences/analysis-process.md. - Risk: This behavior allows the agent to access secrets, API keys, and environment variables stored within the codebase being analyzed.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the codebase being analyzed, creating a surface for indirect prompt injection.
- Ingestion points: The skill reads and searches project files using the
Read,Glob, andGreptools as defined in theSKILL.mdworkflow. - Boundary markers: Absent; there are no instructions or delimiters provided to ensure the agent disregards natural language instructions found within code comments or documentation.
- Capability inventory: The skill utilizes
Bash,Read,Glob, andGreptools for its operations. - Sanitization: Absent; the skill does not filter or validate the content of the analyzed files before the agent processes them.
- [COMMAND_EXECUTION]: The skill uses shell-based tools to perform complex searches and codebase mapping.
- Evidence: The workflow and references rely on executing searches via
GrepandGlobtools to extract information from the filesystem.
Audit Metadata