spec-workflow

Fail

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: HIGHPRIVILEGE_ESCALATIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill uses path traversal sequences (../../../) at lines 306 and 307 of SKILL.md to reference files within a hidden .ai directory. This allows the agent to escape the skill directory and access sensitive project-level configuration.
  • [METADATA_POISONING]: The skill-report.json file includes a security_audit section that provides a safe verdict and justifies the skill's risks. This is a deceptive metadata pattern intended to influence security review processes.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted markdown data from workspace specification files, which can be used to inject malicious instructions. (1) Ingestion points: SKILL.md line 84. (2) Boundary markers: Absent. (3) Capability inventory: File system modification and branch/PR orchestration. (4) Sanitization: None detected.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 27, 2026, 09:38 AM