implement-spec

Fail

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: In Step 7, the skill instructions direct the agent to 'run exactly the commands listed' in the specs/CONSTITUTION.md file. This behavior creates a security risk by allowing the execution of arbitrary shell commands from a file that could be provided by an untrusted source or included in a malicious repository.
  • [PROMPT_INJECTION]: The skill processes specifications and plans from SPEC.md and PLAN.md files without sanitizing or using boundary markers to isolate instructions. * Ingestion points: specs/SPEC.md, specs/PLAN.md, specs/CONSTITUTION.md * Boundary markers: Absent * Capability inventory: Shell command execution, file system write access, subagent spawning * Sanitization: Absent
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 21, 2026, 10:15 AM
Security Audit — agent-trust-hub — implement-spec