kspec-review-plan

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the kspec CLI tool to perform several operations including searching specifications (kspec search), retrieving items (kspec item list, kspec item get), and managing review records (kspec review add, kspec review comment). These commands are used for the skill's primary purpose of project plan auditing.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external plan documents.
  • Ingestion points: Full plan documents are read in Step 1 of the review process.
  • Boundary markers: No specific delimiters are used to wrap or isolate the ingested plan content.
  • Capability inventory: The agent can execute kspec CLI commands to read from and write to a local specification database.
  • Sanitization: No explicit sanitization or filtering is mentioned for the ingested plan data before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 11:15 PM
Security Audit — agent-trust-hub — kspec-review-plan