product-spec
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes product requests and prototype evidence (via
urn:skills:product-request:v1andops-browser), which introduces a surface for indirect instructions. This is addressed by a workflow requirement to explicitly classify and confirm all material statements before they are included in the specification. \n - Ingestion points: Consumes handoffs and prototype data from external triggers and tools.\n
- Boundary markers: Step 5 mandates statement classification (Confirmed, Assumption, Open Question, etc.) before synthesis.\n
- Capability inventory: Authorized to write and update Markdown specification files within the repository.\n
- Sanitization: Relies on manual classification logic and explicit user authorization of artifact writes.\n- [COMMAND_EXECUTION]: The skill uses
git status --shortto verify the state of repository files. This is a read-only command used for environmental awareness before documentation generation.
Audit Metadata