workflow-code-to-spec
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed for developer productivity, focusing on the creation and maintenance of 'Feature Specs' and their synchronization with existing codebase and test suites.
- [PROMPT_INJECTION]: The skill contains instructions for handling compatibility between different agent environments (e.g., 'Ignore Claude-specific mode-switch instructions') and strict execution protocols. These are functional instructions for agent steering and do not attempt to bypass safety filters or override core system behavior.
- [INDIRECT_PROMPT_INJECTION]: The skill processes project-level documentation, which represents a potential attack surface for indirect prompt injection.
- Ingestion points: The skill reads project configuration files (
docs/project-config.json), documentation indexes, and feature specifications located indocs/specs/**. - Boundary markers: The protocol mandates that specifications remain 'tech-free', which serves as a logical constraint, though no explicit technical delimiters for external data are specified.
- Capability inventory: The skill is authorized to use
spawn_agentfor sub-tasks and executes local commands such asgit diff,git log, andnpm run codex:sync. - Sanitization: No specific sanitization or filtering logic is defined for the content read from the project files.
- [DATA_EXPOSURE]: The skill accesses local project paths to perform its functions. It does not reference sensitive system directories (like
.sshor.aws) or perform network operations targeting external, unknown domains for data exfiltration.
Audit Metadata