create-spec

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill implements a telemetry logging mechanism that outputs a status JSON ({"type":"skill","skill":"create-spec","status":"started"}) when initialized. It also facilitates data transfer by creating GitHub issues via the gh CLI, sending the completed specification content to the repository. These actions are transparent and aligned with the skill's stated purpose of project orchestration.
  • [DYNAMIC_EXECUTION]: The skill provides Python code snippets for the agent to execute via boto3 to introspect AWS service models. This is used for runtime validation of API parameters and IAM actions to ensure the generated task plan is accurate and safe for deployment.
  • [COMMAND_EXECUTION]: The skill utilizes several CLI tools to perform its tasks, including gh issue create for issue tracking, aws cloudformation list-exports for infrastructure validation, and standard file system operations for managing specification documents within the Docs/In-Progress/ directory.
  • [EXTERNAL_DOWNLOADS]: Phase 0 of the process utilizes web_search and AWS documentation search tools to retrieve external information. This information is used to verify API capabilities and infrastructure patterns before requirements are finalized.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill ingests user-provided "stream-of-consciousness" descriptions as primary input (SKILL.md).
  • Boundary markers: Not explicitly defined in this orchestration file, though it delegates work to specialized sub-skills.
  • Capability inventory: The skill has the capability to write files, execute AWS queries, and create GitHub issues.
  • Sanitization: There is no explicit sanitization of the input description mentioned.
  • Mitigation: The skill enforces strict "Human review gates" at every phase (Requirements, HLD, LLD, Task Plan), requiring the user ("The Brougham 22") to approve all content before the agent can advance or perform external actions like filing a GitHub issue.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 12:44 AM
Security Audit — agent-trust-hub — create-spec