qa-spec-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted external data during its audit workflow, creating a vulnerability surface.
  • Ingestion points: The skill ingests data from live UI content via Playwright, OpenAPI specifications, requirements documents, and test results (SKILL.md).
  • Boundary markers: The instructions do not define specific delimiters or warnings to prevent the agent from potentially obeying instructions embedded within the audited content.
  • Capability inventory: The skill possesses file system write access for report generation, UI exploration capabilities via Playwright, and repository change tracking via GitHub MCP (SKILL.md).
  • Sanitization: There is no evidence of sanitization or validation protocols for content ingested from external or third-party sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:38 PM
Security Audit — agent-trust-hub — qa-spec-auditor