spec-driven-auto
Warn
Audited by Gen Agent Trust Hub on Apr 13, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: Instructions in Step 1 require the agent to treat all prior conversational context as stale and unreliable, explicitly directing the agent to discard prior instructions which could include safety guardrails.
- [PROMPT_INJECTION]: The skill defines a fully automatic workflow that explicitly avoids mandatory user confirmation for major steps like implementation, verification, and archiving, reducing human oversight.
- [COMMAND_EXECUTION]: The skill executes multiple commands using a local Node.js script located in the skill's script directory to perform repository operations.
- [COMMAND_EXECUTION]: The agent is instructed in Step 4 to run the project's test suite, which involves executing arbitrary code defined within the repository being modified.
Audit Metadata