speckit-constitution

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill focuses on managing a 'project constitution' by reading and updating local files within the .specify/, .github/, and docs/ directories. These operations are transparently described and directly support the skill's stated purpose of governance synchronization.
  • [PROMPT_INJECTION]: The skill features an indirect prompt injection surface as it integrates content from various project documents to generate updates.
  • Ingestion points: Reads from .specify/memory/constitution.md, .specify/templates/*.md, .github/agents/*.md, and README.md.
  • Boundary markers: None identified in the provided instructions.
  • Capability inventory: Limited to reading and overwriting local project markdown and configuration files.
  • Sanitization: No specific sanitization logic is described for the interpolated content. While the surface exists, the risk is negligible as the skill lacks network access, shell execution, or access to sensitive system credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 04:13 AM
Security Audit — agent-trust-hub — speckit-constitution