4-spec

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a document generator and technical advisor. It reads project-related markdown files from the local workspace and generates structured technical specifications. No sensitive data access, network exfiltration, or code execution patterns were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-controlled inputs from project files like prd.md and scope.md. While this exposes a theoretical injection surface common to agents reading user data, the skill lacks dangerous capabilities such as arbitrary code execution or network access that would be required to leverage an injection for malicious purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 03:18 PM
Security Audit — agent-trust-hub — 4-spec