krt-requirements-weaver
Pass
Audited by Gen Agent Trust Hub on May 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves its stated purpose as a requirements engineering assistant. It focuses on structured analysis, gap identification, and quality checking of software requirements.
- [EXTERNAL_DOWNLOADS]: The skill references several external resources in
references/source-literature.md, including links to IEEE, SWEBOK, INCOSE, and Springer. These are reputable academic and professional organizations providing documentation for the methodology used. No automated downloads or script executions are performed from these sources. - [COMMAND_EXECUTION]: The skill mentions writing files to the repository in
references/requirements-workflow.md("Keep file paths repo-relative if writing into the repository"), which is a standard feature for development-oriented agents. It does not utilize arbitrary shell commands or privileged operations. - [PROMPT_INJECTION]: While the skill processes user-supplied data such as client briefs and meeting notes, which theoretically presents an indirect prompt injection surface, the risk is negligible as the skill lacks high-privilege tools (like network access or system modification) that could be abused through such an injection.
Audit Metadata