spec-miner

Warn

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill is programmed to locate and read sensitive configuration files and environment variables to document the system's setup.
  • Evidence: Exploration patterns in SKILL.md target sensitive environment strings like os.environ and config settings.
  • Evidence: The reference guides references/analysis-checklist.md and references/analysis-process.md explicitly instruct the agent to find and read .env files.
  • [PROMPT_INJECTION]: The skill has an inherent attack surface for indirect prompt injection as it processes untrusted source code from external projects.
  • Ingestion points: Code content is read using Read, Grep, and Glob tools as defined in the analysis workflow.
  • Boundary markers: The instructions do not include specific delimiters or warnings to ignore malicious instructions embedded in the source code.
  • Capability inventory: The skill has access to the Bash, Read, Grep, and Glob tools and can write files to the local filesystem.
  • Sanitization: No content filtering or sanitization process is described for the data read from the codebase before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — spec-miner