skills/go7hic/ystack/living-spec/Gen Agent Trust Hub

living-spec

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a documentation management workflow using standard markdown templates. No indicators of malicious activity such as credential theft, remote code execution, or unauthorized network operations were detected.\n- [PROMPT_INJECTION]: The skill instructions define operations that ingest external data sources, including tickets, specifications, and design briefs. While this creates a surface for indirect prompt injection, it is essential for the primary purpose of the skill and is handled via a structured review process.\n
  • Ingestion points: Operations inspect and converge read external files such as originating tickets, acceptance lists, and existing product documentation.\n
  • Boundary markers: The instructions do not specify explicit delimiters or 'ignore' commands for the ingested external content.\n
  • Capability inventory: The skill uses tools for repository exploration, documentation implementation, and verification of observable behavior.\n
  • Sanitization: No specific content filtering or sanitization of ingested data is described, as the agent is expected to interpret and summarize the information.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 03:06 PM
Security Audit — agent-trust-hub — living-spec