dev-spec-reviewer
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a controlled environment for a subagent to review
.planning/SPEC.mdagainst a completeness checklist. It contains no instructions to bypass safety filters or exfiltrate data. - [COMMAND_EXECUTION]: The subagent is granted access to
Bash(read-only),Read,Glob, andGrep. The prompt explicitly restricts the subagent to read-only operations and forbids the use of write or edit tools, which is a security-positive design choice. - [PROMPT_INJECTION]: While the skill uses strong emphasis and 'Iron Law' terminology to enforce workflow consistency, these instructions are aimed at maintaining project quality and do not attempt to override the AI's core safety guardrails or instruction following capabilities.
- [DATA_EXPOSURE]: The skill targets project-specific documentation (
.planning/SPEC.md). There is no evidence of attempts to access sensitive system files, environment variables, or credentials.
Audit Metadata