spec-derive

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates entirely on local specification files and generates code skeletons or documentation. It does not request network access or execute external scripts.
  • [SAFE]: The allowed-tools configuration is restricted to standard file system operations (Read, Write, Grep, Glob) necessary for its stated purpose of reading specs and writing test files.
  • [SAFE]: References to external repositories and documentation points to the author's own official GitHub repository (AsiaOstrich), which is used for licensing and methodology reference.
  • [SAFE]: The skill implements specific 'Anti-Hallucination Rules' designed to prevent the AI from generating content outside the scope of the provided input specifications.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 03:59 AM
Security Audit — agent-trust-hub — spec-derive