spec-creation-updating
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious behavior, obfuscation, or unauthorized access attempts were detected. The skill is purely instructional and provides templates for documentation creation.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill instructions in SKILL.md include a specific safety rule to 'Avoid embedding secrets or private credentials in reusable specs,' which promotes secure documentation practices.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing user requirements into specifications but includes mitigating structure. 1. Ingestion points: User-supplied plans and existing specifications (SKILL.md). 2. Boundary markers: The guidelines mandate the use of 'Machine-checkable contract blocks' and 'app-owned envelope fields' to separate external content from system logic (references/spec-template.md). 3. Capability inventory: No tools are defined in the YAML frontmatter, restricting the agent's actions to text-based generation. 4. Sanitization: Explicit instructions are provided to exclude sensitive credentials from the final output.
Audit Metadata