skills/dzhng/skills/implement-spec/Gen Agent Trust Hub

implement-spec

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon instructions found in external specification files (spec README) and "skills named by the spec".
  • Ingestion points: The workflow starts by reading repository READMEs, spec READMEs, and loading referenced skills (SKILL.md, Step 1).
  • Boundary markers: The instructions do not define explicit delimiters or "ignore" instructions for content sourced from these external files.
  • Capability inventory: The skill has the ability to modify the codebase, execute git commands, spawn concurrent subagents, and perform browser-based verification (SKILL.md, Rules and Workflow sections).
  • Sanitization: The workflow incorporates iterative review processes, including review, refactor-clean, and audit-choices skills, to validate the code and decisions made during implementation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 02:51 AM
Security Audit — agent-trust-hub — implement-spec