skills/irpsv/ai-bro/bro-give-me-spec/Gen Agent Trust Hub

bro-give-me-spec

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes repository code and context to produce its output (SKILL.md, Step 1). This is a standard functional requirement for specification tools. The potential for indirect prompt injection from analyzed code is mitigated by a mandatory review cycle (references/spec-review.md) that utilizes parallel evaluation by a general reviewer and a security-focused sub-agent.
  • [COMMAND_EXECUTION]: The agent is explicitly forbidden from generating implementation plans, code, or diffs. It interacts with the environment through restricted tools like CreatePlan or specific file-writing workflows that include safeguards against unintentional file modification or overwriting.
  • [DATA_EXFILTRATION]: No network access or data exfiltration patterns were identified. All operations are local to the environment, and sub-agents are constrained by read-only directives in their respective prompts (subagents/spec-reviewer-prompt.md, subagents/spec-critical-reviewer-prompt.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 03:52 AM
Security Audit — agent-trust-hub — bro-give-me-spec