spec-interviewer

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The specification generation process creates an indirect prompt injection surface.
  • Ingestion points: User answers are collected via the AskUserQuestion tool as described in Phase 1, 2, and 3 of SKILL.md.
  • Boundary markers: The output markdown template for tasks/spec-YYYYMMDD-{slug}.md does not include delimiters or clear instructions to isolate user input from agent instructions.
  • Capability inventory: The skill uses the Write tool to create the spec file, and the instructions explicitly direct the user to load the resulting file in a new session where the agent will act upon the requirements.
  • Sanitization: No sanitization or escaping is performed on the user's responses before they are saved to the filesystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 05:34 AM
Security Audit — agent-trust-hub — spec-interviewer