spec-miner

Warn

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill contains explicit instructions to locate and potentially read sensitive configuration files and environment variable definitions that are known to contain credentials.
  • Evidence: The 'references/analysis-process.md' and 'references/analysis-checklist.md' files instruct the agent to use Glob: **/.env* to find environment files.
  • Evidence: The 'SKILL.md' file suggests using Grep to discover configuration usage via os\.environ|config\[|settings\..
  • [INDIRECT_PROMPT_INJECTION]: The skill is highly vulnerable to indirect prompt injection because it is designed to ingest and process undocumented or legacy codebases which are considered untrusted data.
  • Ingestion points: Codebase files accessed via Read, Grep, and Glob tools across all project directories as defined in 'references/analysis-process.md'.
  • Boundary markers: Absent. The skill does not provide instructions for the agent to use delimiters or ignore embedded instructions within the processed code.
  • Capability inventory: The agent has access to Bash, Read, Grep, and Glob, enabling it to execute commands or read any file in the accessible environment.
  • Sanitization: Absent. There is no mention of filtering, escaping, or validating the content of the files before they are processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 25, 2026, 05:06 AM
Security Audit — agent-trust-hub — spec-miner