spec-specify
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is entirely instruction-based and does not contain any executable scripts or binary files. Its primary function is to guide an agent through generating a markdown specification file (
spec.md) based on a provided template. - [DATA_EXFILTRATION]: No network operations or data exfiltration vectors were detected. The skill operates exclusively on local project files (
specs/andreferences/). - [COMMAND_EXECUTION]: The instructions do not invoke any shell commands or external processes. It uses standard file-writing behavior expected of an AI agent.
- [PROMPT_INJECTION]: No malicious instruction overrides or safety bypass attempts were found. The 'IMPORTANT' markers used in the text are benign instructional guidelines for the agent's logic flow.
- [CREDENTIALS_UNSAFE]: No hardcoded credentials or attempts to access sensitive system directories (like
.sshor.aws) were identified.
Audit Metadata