speckit-taskstoissues
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local bash script located at
.specify/scripts/bash/check-prerequisites.shfrom the repository root. This allows for arbitrary code execution if the repository being processed is malicious.\n- [DYNAMIC_EXECUTION]: The skill implements an extension hooks system that reads.specify/extensions.ymland dynamically triggers additional commands (e.g.,EXECUTE_COMMAND: {command}). This allows project configuration to control the agent's workflow and execute other skills or tools.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project data to drive high-capability actions like command execution and GitHub issue creation without strict boundaries or sanitization.\n - Ingestion points: Reads and follows instructions from
.specify/extensions.yml,tasks.md, and the output of project scripts.\n - Boundary markers: None identified to separate project data from agent instructions.\n
- Capability inventory: Access to shell execution, dynamic command triggering, and GitHub MCP tools for reading/writing repository data.\n
- Sanitization: No validation or escaping is performed on hook command names or task descriptions before execution or creation.
Recommendations
- AI detected serious security threats
Audit Metadata