spec-driven-development
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow for ingesting and processing untrusted user requirements.
- Ingestion points: User-provided requirements and feature requests used to generate specifications (SKILL.md).
- Boundary markers: The 'Gated Workflow' requires human review and validation at each of the four phases (Specify, Plan, Tasks, Implement).
- Capability inventory: Mentions tool commands for building, testing, and linting, as well as file writes to the
tasks/directory. - Sanitization: Recommends reframing vague instructions into concrete success criteria, which are then subject to human audit before implementation.
- [SAFE]: The skill encourages secure development practices by defining boundaries that explicitly forbid committing secrets or removing failing tests without approval.
- [SAFE]: All referenced file paths (e.g.,
tasks/plan.md,src/) and command templates are standard for development environments and do not indicate malicious intent.
Audit Metadata