speckit-clarify

Warn

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local shell script located at .specify/scripts/bash/check-prerequisites.sh to retrieve environment configuration and directory paths.
  • [DYNAMIC_EXECUTION]: The skill implements a hook system that reads command identifiers from .specify/extensions.yml and executes them via the EXECUTE_COMMAND directive. This allows for the dynamic execution of commands defined within project configuration files.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from various project files without explicit sanitization or boundary markers, combined with capabilities to execute code and modify the file system.
  • Ingestion points: The skill reads FEATURE_SPEC, .specify/extensions.yml, .specify/memory/constitution.md, and FEATURE_DIR/checklists/requirements.md.
  • Boundary markers: No specific delimiters or instructions are used to isolate ingested content from the agent's internal logic.
  • Capability inventory: The agent can execute shell scripts, perform dynamic command execution through hooks, and overwrite local files (specification and checklist files).
  • Sanitization: There are no mechanisms described to validate or sanitize the data retrieved from these files before it influences agent behavior or command generation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 18, 2026, 01:11 PM