kspec-review

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access detected.
  • [COMMAND_EXECUTION]: The skill utilizes local CLI commands including kspec and grep and instructs the agent to run project-specific test suites. These operations are focused on verification within the local development environment.
  • [PROMPT_INJECTION]: The skill is designed to process external code and task descriptions which presents an indirect injection surface. It mitigates this risk by requiring 'Adversarial Investigation' where the agent must independently verify all claims with evidence rather than trusting worker input. Ingestion points: kspec item get, grep, and reading diffs. Boundary markers: Absent. Capability inventory: kspec CLI and project test suites. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 08:49 AM
Security Audit — agent-trust-hub — kspec-review