workflow-feature-spec

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill manages a multi-step workflow ($scout, $investigate, $plan, etc.) and uses the spawn_agent tool to orchestrate sub-agents for complex documentation tasks.
  • [PROMPT_INJECTION]: The instructions include directives such as 'Ignore Claude-specific mode-switch instructions' and 'Strict execution contract.' These are evaluated as framework-specific steering used to maintain consistency across platform versions rather than attempts to bypass safety filters.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect injection as it processes user prompts as workflow context.
  • Ingestion points: The user's prompt is passed as the primary context for the workflow-feature-spec workflow in SKILL.md.
  • Boundary markers: The skill relies on 8-section tech-free template enforcement and mandatory success criteria definitions to bound the AI's behavior.
  • Capability inventory: Capabilities include sub-agent spawning via spawn_agent and filesystem access for reading and updating project documentation in the docs/ directory.
  • Sanitization: The workflow mandates evidence-based claims with specific file:line citations and 'tech-free' output constraints to ground the generated content in repository evidence.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 03:11 PM
Security Audit — agent-trust-hub — workflow-feature-spec