spec-creation-updating

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious behavior, obfuscation, or unauthorized access attempts were detected. The skill is purely instructional and provides templates for documentation creation.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill instructions in SKILL.md include a specific safety rule to 'Avoid embedding secrets or private credentials in reusable specs,' which promotes secure documentation practices.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing user requirements into specifications but includes mitigating structure. 1. Ingestion points: User-supplied plans and existing specifications (SKILL.md). 2. Boundary markers: The guidelines mandate the use of 'Machine-checkable contract blocks' and 'app-owned envelope fields' to separate external content from system logic (references/spec-template.md). 3. Capability inventory: No tools are defined in the YAML frontmatter, restricting the agent's actions to text-based generation. 4. Sanitization: Explicit instructions are provided to exclude sensitive credentials from the final output.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 06:24 PM
Security Audit — agent-trust-hub — spec-creation-updating