realign-spec

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-controlled documentation files which could potentially contain malicious instructions. This is a standard risk for document-processing skills and is managed by agent guardrails. 1. Ingestion points: Markdown files located in docs/specs/ and the docs/specs/INDEX.md file. 2. Boundary markers: The skill does not define specific delimiters or warnings to ignore instructions embedded within the documentation files. 3. Capability inventory: Writing updates to local markdown files and executing the audit-trace helper tool. 4. Sanitization: No explicit sanitization or filtering of the documentation content is performed before processing.
  • [COMMAND_EXECUTION]: The skill instructs the agent to run the audit-trace tool to identify discrepancies in feature specifications. This is an expected use of internal development tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 03:13 AM
Security Audit — agent-trust-hub — realign-spec