spec-discovery
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: No security risks or malicious behaviors were identified. The skill follows structured protocols for project analysis, including evidence-based reasoning and incremental reporting.
- [COMMAND_EXECUTION]: The skill facilitates structural code analysis by instructing the agent to execute a local project script located at
.claude/scripts/code_graph. This is a legitimate and controlled use of internal project tooling. - [SAFE]: The skill has an ingestion surface as it reads local project documentation and source code to identify invariants (Ingestion points: docs/specs/, docs/project-config.json, source code; Boundary markers: absent; Capability inventory: local script execution, local file system writes; Sanitization: absent). This behavior is consistent with its primary purpose and is restricted to local project files.
Audit Metadata