dev-tech-spec-docs

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified. The skill is focused on documentation quality and repository fact-checking.
  • [CREDENTIALS_UNSAFE]: The skill demonstrates a strong security posture by including multiple instructions to avoid credential exposure:
  • SKILL.md states: "Never expose real credentials or imply that an unrun example was tested."
  • CHECKLIST.md includes a check for: "Secrets and actual credentials were not included in examples or results."
  • PATTERNS.md warns against using real API keys and suggests placeholders like ${API_KEY}.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests data from the repository (code, config, and documents) to generate documentation, it includes defensive instructions to verify facts against the source of truth and to report gaps rather than inventing values. This reduces the risk of the agent being misled by malicious or contradictory repository content.
  • [COMMAND_EXECUTION]: The skill instructs the agent to run repository commands (like tests or scripts) "when safe and proportionate" to verify documentation accuracy. This is a standard functional requirement for documentation agents and is accompanied by guidelines to report results and uncertainties clearly.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 08:45 AM
Security Audit — agent-trust-hub — dev-tech-spec-docs