spec-index
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions that attempt to override standard agent behavior or platform-specific constraints. Specifically, it directs the agent to "Ignore Claude-specific mode-switch instructions when they appear" and mandates a "Strict execution contract" that enforces the skill's internal protocol over external guidelines.- [INDIRECT_PROMPT_INJECTION]: The skill processes external, potentially untrusted data which could be manipulated to influence agent behavior.
- Ingestion points: The skill reads from Feature Specs located in
docs/specs/{Bucket}/README.*.md. - Boundary markers: Absent. There are no instructions to use delimiters or ignore instructions embedded within the extracted spec content.
- Capability inventory: The skill has file-write access (creating
INDEX.md, etc.) and the ability to spawn subagents (spawn_agent). - Sanitization: Absent. The protocol does not include steps to sanitize or validate extracted text before writing it to the generated artifacts.- [COMMAND_EXECUTION]: The skill invokes platform-specific tools and subagent processes.
- Evidence: The skill instructions explicitly mention using
spawn_agentfor optimization and calling other skills such as$scout,$project-init, and$sync-codex.
Audit Metadata