spec-miner
Warn
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill contains explicit instructions to locate and potentially read sensitive configuration files and environment variable definitions that are known to contain credentials.
- Evidence: The 'references/analysis-process.md' and 'references/analysis-checklist.md' files instruct the agent to use
Glob: **/.env*to find environment files. - Evidence: The 'SKILL.md' file suggests using
Grepto discover configuration usage viaos\.environ|config\[|settings\.. - [INDIRECT_PROMPT_INJECTION]: The skill is highly vulnerable to indirect prompt injection because it is designed to ingest and process undocumented or legacy codebases which are considered untrusted data.
- Ingestion points: Codebase files accessed via
Read,Grep, andGlobtools across all project directories as defined in 'references/analysis-process.md'. - Boundary markers: Absent. The skill does not provide instructions for the agent to use delimiters or ignore embedded instructions within the processed code.
- Capability inventory: The agent has access to
Bash,Read,Grep, andGlob, enabling it to execute commands or read any file in the accessible environment. - Sanitization: Absent. There is no mention of filtering, escaping, or validating the content of the files before they are processed by the agent.
Audit Metadata