spec-miner

Fail

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation link https://jeffallan.github.io/claude-skills/skills/workflow/spec-miner/ included in the skill has been flagged as malicious by automated reputation scanners.
  • [DATA_EXFILTRATION]: The skill's analysis instructions in references/analysis-checklist.md and references/analysis-process.md explicitly direct the agent to locate and read sensitive configuration files, such as environment files (.env) and internal configuration modules, which can lead to the exposure of secrets and system credentials.
  • [METADATA_POISONING]: The main SKILL.md file has been flagged as malicious by file reputation scanners. Furthermore, there is a discrepancy between the author identifier in the frontmatter (Jeffallan) and the provided skill author context (emmraan).
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external codebases but provides no safety boundaries or sanitization protocols, making the agent vulnerable to instructions hidden within the analyzed data.
  • Ingestion points: Core workflow and analysis scripts in SKILL.md, references/analysis-checklist.md, and references/analysis-process.md.
  • Boundary markers: Absent; no instructions are provided to the agent to disregard embedded commands or use delimiters for external data.
  • Capability inventory: The agent is granted access to Bash, Read, Grep, and Glob tools for exploration and processing.
  • Sanitization: Absent; no validation or filtering is applied to the content read from external source files.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 6, 2026, 11:36 AM
Security Audit — agent-trust-hub — spec-miner