write-requirements

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a standard software engineering workflow for writing and reviewing requirements.
  • [DATA_EXPOSURE]: The skill performs a 'code-claim check' by reading project source code and documentation to verify the accuracy of requirement criteria. This file access is limited to the project context and is used for verification purposes only; no sensitive system paths or credentials are targeted, and no network exfiltration is attempted.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from brainstorm outcomes and existing source code to generate requirements. This represents a standard indirect prompt injection surface. The risk is mitigated by the structured markdown output format and the requirement for explicit human approval ('Status: Approved') before the agent proceeds to the next phase of development.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 05:48 AM
Security Audit — agent-trust-hub — write-requirements