speckit-initial
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the AI agent to execute the
specify initcommand. This is a legitimate operation used to bootstrap project configurations and register slash commands like/speckit.planfor the agent's environment. - [EXTERNAL_DOWNLOADS]: The initialization process involves pulling the
.specify/directory, which contains project memory, scripts, and templates. The skill references the official GitHub repository for Spec Kit as the source for these resources, which is a recognized and well-known service for developer tools.
Audit Metadata