spec-kit-plan
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources such as specification files (
spec.md) and feature descriptions to generate its output. While it does not explicitly define boundary markers to separate instructions from the data it processes, the risk is negligible as the skill lacks high-risk capabilities. Its operations are restricted to reading and writing local documentation, with no access to network tools, environment secrets, or shell execution.
Audit Metadata