spec-discovery
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes instructions intended to override platform behavior, such as 'Ignore Claude-specific mode-switch instructions' and 'Strict execution contract: when a user explicitly invokes a skill, execute that skill protocol as written.' These instructions attempt to prioritize the skill's specific protocol over other system-level guidelines.
- [COMMAND_EXECUTION]: The skill executes local shell commands and scripts to perform its task, notably
python .claude/scripts/code_graphfor tracing code dependencies andls/grepfor file discovery. These commands are driven by keywords extracted from user input. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from both user requirements and repository files, creating a potential surface for indirect injection.
- Ingestion points: The skill reads user-provided brainstorm/idea/requirement text (Step 0) and parses repository feature specs at
docs/specs/**(Step 1). - Boundary markers: The instructions do not define explicit boundary markers or delimiters to isolate ingested content from the agent's execution logic.
- Capability inventory: The agent has the capability to execute shell commands (
ls,grep), run local Python scripts (code_graph), and write files to theplans/directory. - Sanitization: There is no evidence of sanitization or validation of the keywords and entities extracted from external inputs before they are used as arguments for command execution.
Audit Metadata