specforge-intake
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Node.js scripts
status.mjsandcreate-change.mjslocated within the.specforge/tools/directory to manage the project workflow. - [DATA_EXPOSURE]: The agent reads local project files including
attention.md,registry.yaml, and project specifications from the.specforge/directory to gather necessary context. - [PROMPT_INJECTION]: The skill processes untrusted user input to generate project documentation. 1. Ingestion points: user requests and
original-request.md. 2. Boundary markers: uses.specforge/rules/boundaries.mdfor scope control. 3. Capability inventory: file system writes and local shell execution. 4. Sanitization: implementsspec-quality.mdrules to identify and mark ambiguity with[NEEDS CLARIFICATION].
Audit Metadata