workflow-spec-sync

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by ingesting untrusted user prompts and repository documentation files.\n
  • Ingestion points: Processes user-provided context and project reference files such as docs/project-config.json and docs/project-reference/* as specified in the Codex Project-Reference Loading section.\n
  • Boundary markers: There are no explicit delimiters or 'ignore embedded instructions' warnings defined for the user-provided context within the SKILL.md file.\n
  • Capability inventory: The skill allows spawning sub-agents (spawn_agent tool) and performs file operations including writing report files (plans/reports/*) and updating project specification and test documentation.\n
  • Sanitization: The skill includes mandatory 'AI Mistake Prevention' and 'Critical Thinking Mindset' protocols that require file:line evidence for all claims and manual verification of generated content, which serves as a mitigation layer against malicious data processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — workflow-spec-sync