write-spec

Pass

Audited by Gen Agent Trust Hub on Jun 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a 'Spec Skeptic' agent as a mandatory quality gate for all architectural and data designs. This adversarial review process is a security best practice that ensures deliverables are scrutinized for consistency and compliance before being finalized.
  • [SAFE]: Explicit data protection policies are defined in the 'Shared Principles' section, which strictly forbids the inclusion of credentials, API keys, or personally identifiable information (PII) in agent messages, prompts, or checkpoint files.
  • [SAFE]: The orchestration flow enforces strict 'Write Safety' boundaries, requiring agents to write only to role-specific progress and architecture files. This isolation prevents unauthorized modification of shared files or project configuration by individual agents.
  • [SAFE]: The skill demonstrates defensive instruction design by requiring agents to 'Halt on ambiguity' and surface missing information to the human lead, mitigating the risk of agents making insecure assumptions when processing user stories.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 29, 2026, 02:02 PM