speckit-analyze

Warn

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local shell script located at .specify/scripts/bash/check-prerequisites.sh to initialize the analysis context and verify environment state.
  • [DYNAMIC_EXECUTION]: The skill implements a 'Pre-Execution' and 'Post-Report' hook mechanism that reads command names from .specify/extensions.yml. It dynamically constructs and invokes these commands using EXECUTE_COMMAND based on the file content.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its ingestion of untrusted project documents that influence command execution flow.
  • Ingestion points: Untrusted data is read from .specify/extensions.yml, spec.md, plan.md, and tasks.md.
  • Boundary markers: Absent. The instructions do not specify the use of delimiters or 'ignore' instructions when processing external file content.
  • Capability inventory: The skill possesses the capability to execute shell scripts and trigger additional agent commands via the hook system.
  • Sanitization: Absent. Beyond a simple character replacement in command names, there is no validation or filtering performed on the data ingested from the project files.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 18, 2026, 01:11 PM