kspec-review
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data access detected.
- [COMMAND_EXECUTION]: The skill utilizes local CLI commands including
kspecandgrepand instructs the agent to run project-specific test suites. These operations are focused on verification within the local development environment. - [PROMPT_INJECTION]: The skill is designed to process external code and task descriptions which presents an indirect injection surface. It mitigates this risk by requiring 'Adversarial Investigation' where the agent must independently verify all claims with evidence rather than trusting worker input. Ingestion points:
kspec item get,grep, and reading diffs. Boundary markers: Absent. Capability inventory:kspecCLI and project test suites. Sanitization: Absent.
Audit Metadata