specstory-guard

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess calls in scripts/setup.py and scripts/guard.py to execute git commands for repository discovery and to coordinate the execution of its internal setup and scanning scripts.
  • [PERSISTENCE]: The skill installs a pre-commit hook in the repository's .git/hooks directory. This is the intended functionality of the skill, designed to automatically check for secrets before code is committed.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted chat history data from .specstory/history files. It mitigates the risk of accidental exposure by redacting detected secrets in the output snippets it presents to the user.
  • [SAFE]: The skill performs all operations locally, uses standard Python libraries, and includes comprehensive documentation for secret remediation and pattern matching.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — specstory-guard