speckit-workflow-step

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the ingestion of external data sources.
  • Ingestion points: The specify workflow step catalog add <url> command allows adding external, user-defined URLs as sources for step type catalogs. Additionally, specify workflow step search <query> and specify workflow step info <step-id> fetch and display metadata from these external sources.
  • Boundary markers: The instructions do not define explicit boundary markers or instructions for the agent to ignore potentially malicious content within these external catalogs.
  • Capability inventory: The skill uses the specify CLI to install (add) and manage workflow components which are subsequently executed as part of workflows.
  • Sanitization: There is no mention of sanitization or verification of the content fetched from remote catalogs before it is displayed to the agent or used for installation.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of shell commands through the specify CLI. While these commands are for managing workflow components, they represent the primary interface through which the agent interacts with the underlying system.
  • [EXTERNAL_DOWNLOADS]: The skill includes functionality to download external content via specify workflow step add and specify workflow step catalog add. These commands fetch packages and configuration from remote URLs, which constitutes an external data dependency.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 11:49 PM
Security Audit — agent-trust-hub — speckit-workflow-step