spec

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is a logic-only instruction set for generating technical documentation. It does not include scripts, binaries, or remote network operations.
  • [PROMPT_INJECTION]: The skill ingests user-provided requirements through the USER_PROMPT variable to generate technical plans. While this represents a data ingestion point, the output is restricted to markdown documentation and the skill does not automate the execution of generated commands. 1. Ingestion points: USER_PROMPT ($1). 2. Boundary markers: Absent. 3. Capability inventory: Local file system write (specs/ directory). 4. Sanitization: Absent.
  • [NO_CODE]: The skill consists entirely of instructional markdown in the SKILL.md file and does not reference or bundle any external scripts or dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 08:06 AM
Security Audit — agent-trust-hub — spec