spec-index

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that attempt to override standard agent behavior or platform-specific constraints. Specifically, it directs the agent to "Ignore Claude-specific mode-switch instructions when they appear" and mandates a "Strict execution contract" that enforces the skill's internal protocol over external guidelines.- [INDIRECT_PROMPT_INJECTION]: The skill processes external, potentially untrusted data which could be manipulated to influence agent behavior.
  • Ingestion points: The skill reads from Feature Specs located in docs/specs/{Bucket}/README.*.md.
  • Boundary markers: Absent. There are no instructions to use delimiters or ignore instructions embedded within the extracted spec content.
  • Capability inventory: The skill has file-write access (creating INDEX.md, etc.) and the ability to spawn subagents (spawn_agent).
  • Sanitization: Absent. The protocol does not include steps to sanitize or validate extracted text before writing it to the generated artifacts.- [COMMAND_EXECUTION]: The skill invokes platform-specific tools and subagent processes.
  • Evidence: The skill instructions explicitly mention using spawn_agent for optimization and calling other skills such as $scout, $project-init, and $sync-codex.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — spec-index