skills/ericrisco/rsc-harness/specify/Gen Agent Trust Hub

specify

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local validation command npm run spec:gate <path> to verify that generated specification files comply with the required template structure and mandatory sections.
  • [INDIRECT_PROMPT_INJECTION]: The skill features a data ingestion surface where it reads from local project configuration and documentation files to inform its output.
  • Ingestion points: Untrusted data enters the agent context via 02-DOCS/wiki/harness/user-profile.md, 02-DOCS/wiki/sdd/constitution.md, and 02-DOCS/wiki/sdd/config.yaml.
  • Boundary markers: The skill enforces the use of a strict markdown template (references/spec-template.md) and structural Given/When/Then blocks for acceptance criteria.
  • Capability inventory: The skill possesses the ability to write files to the 02-DOCS/wiki/sdd/specs/ directory and execute project-local validation scripts.
  • Sanitization: While explicit sanitization is not detailed, the skill focuses on extracting specific behavioral and technical parameters to guide generation rather than executing content from these files.
  • [TIME_DELAYED_CONDITIONAL]: The skill implements a versioning mechanism that gates the requirement of certain sections (e.g., 'Cost of not building it') based on the document's timestamp (on or after 2026-09-06). This is a benign conditional check for phasing in documentation standards.
  • [DYNAMIC_EXECUTION]: The skill utilizes platform-native subagents for automated peer review ('Fresh-eyes spec review') and supports dynamic model routing as configured in the project's SDD settings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — specify