accelint-qrspi-apply
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes the
openspecandgitCLI tools to manage development workflows. These actions are performed locally and are consistent with the skill's intended purpose. - [PROMPT_INJECTION]: The skill incorporates content from the local
tasks.mdfile (Ingestion point) into instructions for sub-agents. Boundary markers are used to isolate task slices, such as 'Focus exclusively on Slice N'. The capability inventory includes file system access and shell command execution via the OpenSpec CLI. No explicit sanitization of task content is performed, but the workflow is inherently scoped to implementation tasks. - [SAFE]: No malicious patterns, such as hardcoded credentials, unauthorized remote downloads, or data exfiltration, were detected during the analysis.
Audit Metadata