crud-with-spec-kit

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of documentation and metadata. No scripts, binaries, or active configuration steps are present within the skill files.\n- [INDIRECT_PROMPT_INJECTION]: The skill describes a process for reading Spec-Kit files to generate backend routes and frontend components. This ingestion of untrusted data into a code-writing agent context constitutes an indirect prompt injection surface.\n
  • Ingestion points: External Spec-Kit specification files described in the input requirements and prompt templates.\n
  • Boundary markers: Absent; no delimiters or instructions to ignore embedded commands within the specification data are defined.\n
  • Capability inventory: The skill guides the agent to perform complex file-writing tasks including generating API endpoints, client models, UI logic, and test cases.\n
  • Sanitization: No validation, escaping, or sanitization of the input specification content is prescribed to mitigate potential injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 09:38 AM