spec-forge-readiness

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were detected. The skill follows best practices for workflow automation, including explicit approval steps and operation in plan-only mode.
  • [COMMAND_EXECUTION]: The skill invokes the vendor-owned CLI spec-forge-cli for operations such as merging artifacts, checking gates, and advancing stages. These commands are integral to the skill's functionality and are performed on local specification files within the project directory.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill manages internal project metadata and YAML specifications. It does not access sensitive system directories, credentials, or perform network operations to non-whitelisted domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 09:29 AM
Security Audit — agent-trust-hub — spec-forge-readiness