spec-verify

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No patterns of instruction override, safety bypass, or role-play injection were detected in the skill instructions or metadata.
  • [DATA_EXFILTRATION]: The skill only utilizes Read, Grep, and Glob tools for local file analysis. It does not attempt to access sensitive system paths (e.g., .ssh, .aws) or perform network requests to external domains.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads implementation details from the user-provided SPEC.md file. This ingestion point is managed through specific analysis instructions and requires the creation of a review file (SPEC-REVIEW.md) or a summary, maintaining a safe operational boundary with a human-in-the-loop for feedback.
  • [REMOTE_CODE_EXECUTION]: No package installations, remote script downloads, or dynamic code execution patterns were identified in the skill workflow or reference sections.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 01:41 PM
Security Audit — agent-trust-hub — spec-verify