flow-spec

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific external data such as ticket.md, source code, and documentation to generate specifications.
  • Ingestion points: The agent is instructed to read ticket.md, the brief, AGENTS.md, CLAUDE.md, and source code files.
  • Boundary markers: No specific boundary markers or safety delimiters are defined for the external data ingestion.
  • Capability inventory: The skill performs file system read/write operations and triggers other workflow skills like flow-review and flow-plan.
  • Sanitization: The instructions do not include data validation or sanitization for the content read from external files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:04 AM
Security Audit — agent-trust-hub — flow-spec