speckit-check
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run the
specify checkcommand to verify the installation and availability of required development tools. This is a standard diagnostic procedure. - [EXTERNAL_DOWNLOADS]: The skill references the official GitHub repository for Spec Kit (github.com/github/spec-kit), which is a well-known and trusted source for documentation and verification.
- [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface when processing the output from the check command. Ingestion point: CLI output from
specify checkas described in SKILL.md. Boundary markers: None are specified in the workflow instructions. Capability inventory: The skill provides recommendations for subsequent actions like runningspeckit-installorspeckit-initial. Sanitization: No sanitization of the tool output is performed before interpretation.
Audit Metadata