speckit-analyze
Warn
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local shell script located at
.specify/scripts/bash/check-prerequisites.shto initialize the analysis context and verify environment state. - [DYNAMIC_EXECUTION]: The skill implements a 'Pre-Execution' and 'Post-Report' hook mechanism that reads command names from
.specify/extensions.yml. It dynamically constructs and invokes these commands usingEXECUTE_COMMANDbased on the file content. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its ingestion of untrusted project documents that influence command execution flow.
- Ingestion points: Untrusted data is read from
.specify/extensions.yml,spec.md,plan.md, andtasks.md. - Boundary markers: Absent. The instructions do not specify the use of delimiters or 'ignore' instructions when processing external file content.
- Capability inventory: The skill possesses the capability to execute shell scripts and trigger additional agent commands via the hook system.
- Sanitization: Absent. Beyond a simple character replacement in command names, there is no validation or filtering performed on the data ingested from the project files.
Audit Metadata