speckit-plan

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local shell scripts located in .specify/scripts/bash/ to facilitate project setup and update agent context files.
  • [COMMAND_EXECUTION]: Provides explicit guidance on escaping single quotes in shell arguments to protect against command injection when processing user-supplied constraints.
  • [COMMAND_EXECUTION]: Dynamically generates and manages research and design artifacts like research.md and data-model.md through a structured planning workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 04:13 AM
Security Audit — agent-trust-hub — speckit-plan