kiro-spec-tasks

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill implements a structured workflow for generating and reviewing tasks. It performs file read and write operations on specific local project files within the .kiro/ directory but does not execute arbitrary shell commands or system-level operations.
  • [DATA_EXFILTRATION]: No network operations, such as curl, wget, or API calls to external domains, were found. All data processing is confined to the local project environment.
  • [PROMPT_INJECTION]: The instructions focus on establishing strict functional constraints for task generation (e.g., requirement mapping, boundary annotations). There are no patterns suggesting attempts to bypass safety filters or override the agent's core behavioral guidelines.
  • [EXTERNAL_DOWNLOADS]: The skill relies on local rules and templates stored within the skill's directory or the project's configuration. It does not attempt to download external scripts, packages, or executable content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 01:15 AM
Security Audit — agent-trust-hub — kiro-spec-tasks