init-spec
Pass
Audited by Gen Agent Trust Hub on Jun 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is to read codebase metadata and documentation to help users initialize a living specification. No unauthorized network access, credential theft, or malicious code execution patterns were found.
- [SAFE]: While the skill processes untrusted data from the codebase (source code, README files, agent documentation) which is an indirect prompt injection surface, the risk is mitigated by a required human ratification step where the user must approve or edit the proposed content before it is recorded.
Audit Metadata