crud-with-spec-kit
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of documentation and metadata. No scripts, binaries, or active configuration steps are present within the skill files.\n- [INDIRECT_PROMPT_INJECTION]: The skill describes a process for reading Spec-Kit files to generate backend routes and frontend components. This ingestion of untrusted data into a code-writing agent context constitutes an indirect prompt injection surface.\n
- Ingestion points: External Spec-Kit specification files described in the input requirements and prompt templates.\n
- Boundary markers: Absent; no delimiters or instructions to ignore embedded commands within the specification data are defined.\n
- Capability inventory: The skill guides the agent to perform complex file-writing tasks including generating API endpoints, client models, UI logic, and test cases.\n
- Sanitization: No validation, escaping, or sanitization of the input specification content is prescribed to mitigate potential injection.
Audit Metadata