tech-spec
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses grep-based discovery (e.g.,
grep -r "{command-handler-marker}") to count operations and handlers in the source code. These commands are templates intended for local repository analysis and do not interact with external systems or execute untrusted input. - [EXTERNAL_DOWNLOADS]: The skill does not perform any network operations or external downloads. It operates entirely on the local file system using the provided
.mjsscript. - [REMOTE_CODE_EXECUTION]: There is no remote code execution. The provided JavaScript script (
generate-tech-specs.mjs) performs file system operations (read/write/readdir) scoped to the repository root to generate documentation. - [DATA_EXFILTRATION]: No data exfiltration patterns were detected. The skill explicitly includes a 'No secrets' verification step to ensure credentials or connection strings are not included in the generated documentation.
- [PROMPT_INJECTION]: The skill contains strict internal protocols (C1-C9) to prevent the AI from authoring business content or overriding safety guidelines. It emphasizes mechanical derivation over judgment to maintain idempotency.
- [CREDENTIALS_SAFE]: The skill includes a specific check in Step 4 to ensure no secrets, connection strings, or credentials encountered during the scan are written to the output files.
Audit Metadata