spec-writer

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a structured, interactive interview process to generate professional Markdown documentation. Its behavior is entirely consistent with its stated purpose of assisting in requirements engineering.
  • [SAFE]: The skill uses local reference files (located in the references/ directory) to provide expert guidance. This ensures that the agent's logic is grounded in industry-standard practices rather than external or untrusted sources.
  • [SAFE]: All external URLs found within the reference documentation point to highly reputable and trusted sources, including standards bodies (IEEE, ISO), major technology vendors (Google, Amazon, Microsoft, Uber), and well-known industry leaders (Martin Fowler, Alistair Cockburn). These references are used for educational and research purposes and do not trigger any automated downloads or executions.
  • [SAFE]: File operations are restricted to reading the skill's own reference files and writing generated documents to the standard /mnt/user-data/outputs/ directory. There is no evidence of attempts to access sensitive system files or credentials.
  • [SAFE]: The skill's interaction model includes standard safety features, such as providing free-text escape hatches for all structured questions and summarizing captured context before proceeding to the next section.
  • [SAFE]: No obfuscation, dynamic code generation, or persistence mechanisms were identified across any of the six analyzed files.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 01:58 AM
Security Audit — agent-trust-hub — spec-writer