tech-spec

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses grep-based discovery (e.g., grep -r "{command-handler-marker}") to count operations and handlers in the source code. These commands are templates intended for local repository analysis and do not interact with external systems or execute untrusted input.
  • [EXTERNAL_DOWNLOADS]: The skill does not perform any network operations or external downloads. It operates entirely on the local file system using the provided .mjs script.
  • [REMOTE_CODE_EXECUTION]: There is no remote code execution. The provided JavaScript script (generate-tech-specs.mjs) performs file system operations (read/write/readdir) scoped to the repository root to generate documentation.
  • [DATA_EXFILTRATION]: No data exfiltration patterns were detected. The skill explicitly includes a 'No secrets' verification step to ensure credentials or connection strings are not included in the generated documentation.
  • [PROMPT_INJECTION]: The skill contains strict internal protocols (C1-C9) to prevent the AI from authoring business content or overriding safety guidelines. It emphasizes mechanical derivation over judgment to maintain idempotency.
  • [CREDENTIALS_SAFE]: The skill includes a specific check in Step 4 to ensure no secrets, connection strings, or credentials encountered during the scan are written to the output files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:22 PM
Security Audit — agent-trust-hub — tech-spec