spec-driven-dev

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a standard development workflow and documentation templates for Power Platform projects. Analysis of the instructions, metadata, and embedded templates confirms the absence of malicious patterns, such as prompt injection, data exfiltration, or unauthorized command execution.
  • [PROMPT_INJECTION]: The skill outlines a process where agents ingest and act upon specification files. While this creates a surface for indirect prompt injection, it is an inherent part of the documented development process and the primary purpose of the skill. The skill encourages best practices such as approval gates and verification steps which mitigate operational risks.
  • Ingestion points: Agents read component specification files (e.g., spec-tables.md).
  • Boundary markers: Not explicitly required within the markdown templates provided.
  • Capability inventory: The agents are intended to use Power Platform tools (dataverse-web-api, pac CLI) to implement the specs.
  • Sanitization: No specific sanitization instructions are included for the natural language specifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 02:03 AM
Security Audit — agent-trust-hub — spec-driven-dev