speckit-clarify
Warn
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local shell script located at
.specify/scripts/bash/check-prerequisites.shto retrieve environment configuration and directory paths. - [DYNAMIC_EXECUTION]: The skill implements a hook system that reads command identifiers from
.specify/extensions.ymland executes them via theEXECUTE_COMMANDdirective. This allows for the dynamic execution of commands defined within project configuration files. - [INDIRECT_PROMPT_INJECTION]: The skill processes content from various project files without explicit sanitization or boundary markers, combined with capabilities to execute code and modify the file system.
- Ingestion points: The skill reads
FEATURE_SPEC,.specify/extensions.yml,.specify/memory/constitution.md, andFEATURE_DIR/checklists/requirements.md. - Boundary markers: No specific delimiters or instructions are used to isolate ingested content from the agent's internal logic.
- Capability inventory: The agent can execute shell scripts, perform dynamic command execution through hooks, and overwrite local files (specification and checklist files).
- Sanitization: There are no mechanisms described to validate or sanitize the data retrieved from these files before it influences agent behavior or command generation.
Audit Metadata