specstory-guard
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocesscalls inscripts/setup.pyandscripts/guard.pyto executegitcommands for repository discovery and to coordinate the execution of its internal setup and scanning scripts. - [PERSISTENCE]: The skill installs a pre-commit hook in the repository's
.git/hooksdirectory. This is the intended functionality of the skill, designed to automatically check for secrets before code is committed. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted chat history data from
.specstory/historyfiles. It mitigates the risk of accidental exposure by redacting detected secrets in the output snippets it presents to the user. - [SAFE]: The skill performs all operations locally, uses standard Python libraries, and includes comprehensive documentation for secret remediation and pattern matching.
Audit Metadata