spec-discovery

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: No security risks or malicious behaviors were identified. The skill follows structured protocols for project analysis, including evidence-based reasoning and incremental reporting.
  • [COMMAND_EXECUTION]: The skill facilitates structural code analysis by instructing the agent to execute a local project script located at .claude/scripts/code_graph. This is a legitimate and controlled use of internal project tooling.
  • [SAFE]: The skill has an ingestion surface as it reads local project documentation and source code to identify invariants (Ingestion points: docs/specs/, docs/project-config.json, source code; Boundary markers: absent; Capability inventory: local script execution, local file system writes; Sanitization: absent). This behavior is consistent with its primary purpose and is restricted to local project files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 03:12 PM
Security Audit — agent-trust-hub — spec-discovery