spec-constitution

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill creates and updates a constitution file designed to govern the behavior of future agent runs. It ingests user-provided rules and interpolates them directly into the core principles of the project without sanitization or boundary markers, which could allow malicious instructions to be embedded in the project's governance documents.
  • Ingestion points: User-provided project rules processed in steps 4 and 5 of SKILL.md.
  • Boundary markers: Absent; user input is integrated directly into the markdown structure of the constitution.
  • Capability inventory: The skill has the capability to write to the file system (specs/constitution.md).
  • Sanitization: None; user input is folded into existing principles or added as new ones without validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 03:54 AM
Security Audit — agent-trust-hub — spec-constitution