spec-forge-components

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill manages the development workflow by invoking the vendor-specific spec-forge-cli tool. It executes subcommands such as resolve, apply, artifact, and gate to process and persist component details. These invocations incorporate user-defined parameters, including the project directory and specification identifiers.
  • [SAFE]: Analysis of the skill's instructions and configuration confirms that all file and command operations are confined to the local project environment. No malicious patterns, such as data exfiltration to external servers, obfuscation of intent, or the use of hardcoded credentials, were identified. The skill acts as a transparent interface for structured project management tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 09:29 AM
Security Audit — agent-trust-hub — spec-forge-components