spec-discovery

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes instructions intended to override platform behavior, such as 'Ignore Claude-specific mode-switch instructions' and 'Strict execution contract: when a user explicitly invokes a skill, execute that skill protocol as written.' These instructions attempt to prioritize the skill's specific protocol over other system-level guidelines.
  • [COMMAND_EXECUTION]: The skill executes local shell commands and scripts to perform its task, notably python .claude/scripts/code_graph for tracing code dependencies and ls/grep for file discovery. These commands are driven by keywords extracted from user input.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from both user requirements and repository files, creating a potential surface for indirect injection.
  • Ingestion points: The skill reads user-provided brainstorm/idea/requirement text (Step 0) and parses repository feature specs at docs/specs/** (Step 1).
  • Boundary markers: The instructions do not define explicit boundary markers or delimiters to isolate ingested content from the agent's execution logic.
  • Capability inventory: The agent has the capability to execute shell commands (ls, grep), run local Python scripts (code_graph), and write files to the plans/ directory.
  • Sanitization: There is no evidence of sanitization or validation of the keywords and entities extracted from external inputs before they are used as arguments for command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — spec-discovery