implement-spec
Warn
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill instructions require the agent to "Load any skills named by the spec." This constitutes dynamic loading of executable skills where the targets are determined at runtime by the content of a specification file rather than being statically defined, which can lead to unexpected capability expansion.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from project specification files that could contain malicious instructions intended to hijack the agent or its subagents.
- Ingestion points: Specification README files, choices ledgers, and list of skill names extracted from the specification.
- Boundary markers: There are no explicit instructions or delimiters defined to separate untrusted specification data from internal logic, nor are there warnings for the agent to ignore embedded instructions within these files.
- Capability inventory: The skill has the ability to spawn concurrent subagents, perform complex git operations (including worktree management), modify the project filesystem, and load new agent skills.
- Sanitization: No validation or sanitization mechanisms are described for the contents of the specification files before they are used to influence orchestrator behavior or subagent delegation.
Audit Metadata