speckit-check

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run the specify check command to verify the installation and availability of required development tools. This is a standard diagnostic procedure.
  • [EXTERNAL_DOWNLOADS]: The skill references the official GitHub repository for Spec Kit (github.com/github/spec-kit), which is a well-known and trusted source for documentation and verification.
  • [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface when processing the output from the check command. Ingestion point: CLI output from specify check as described in SKILL.md. Boundary markers: None are specified in the workflow instructions. Capability inventory: The skill provides recommendations for subsequent actions like running speckit-install or speckit-initial. Sanitization: No sanitization of the tool output is performed before interpretation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 04:11 PM
Security Audit — agent-trust-hub — speckit-check