spec
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs standard procedural documentation tasks using local file context. It does not exhibit malicious behavior such as exfiltration, persistence, or unauthorized command execution.
- [PROMPT_INJECTION]: The skill ingests content from external files like 'seed.md' and 'decisions.md', creating an indirect prompt injection surface. (1) Ingestion points: Reads files from 'docs/threads/'. (2) Boundary markers: Absent. (3) Capability inventory: File-write to 'spec.md'. (4) Sanitization: Absent. The risk is considered minimal as it does not execute code or perform network requests based on the input.
Audit Metadata