spec-research
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security issues were detected. The skill's behaviors, such as reading project files and investigating external sources, are consistent with its documented purpose.- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by ingesting external data (Step 3) and maintaining the capability to execute code via proofs of concept (Step 3). This is documented as a functional surface rather than a malicious finding.
- Ingestion points: Step 3 (external documentation, APIs, library comparisons)
- Boundary markers: Absent
- Capability inventory: Step 3 ('Run a proof of concept')
- Sanitization: Absent- [COMMAND_EXECUTION]: The skill involves the execution of code for technical validation through proofs of concept (Step 3). This execution is limited to the scope of the research task and is a primary feature of the skill.
Audit Metadata