write-product-spec

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions focus on generating markdown documentation and using standard GitHub issue tracking for the bholmesdev/hubble.md repository.
  • [PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection by processing external data.
  • Ingestion points: GitHub issue descriptions accessed via the 'gh' tool and user feature requests.
  • Boundary markers: The skill does not define specific delimiters to separate untrusted external data from instructions.
  • Capability inventory: The skill utilizes file writing to the 'specs/' directory and GitHub issue management via the 'gh' CLI tool.
  • Sanitization: No explicit sanitization or validation methods are described for handling external text data before it is incorporated into the documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 11:41 PM
Security Audit — agent-trust-hub — write-product-spec