kspec-triage-inbox
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized access to sensitive data were detected. The skill uses a proprietary CLI tool (kspec) for task management and triage operations.
- [PROMPT_INJECTION]: The skill involves processing external data (inbox items and observations), which presents an indirect prompt injection surface.
- Ingestion points:
kspec inbox listandkspec meta observations(SKILL.md). - Boundary markers: Absent. The instructions do not specify delimiters or warnings to ignore instructions embedded in the external content.
- Capability inventory: Shell command execution via the
kspecCLI suite (e.g.,kspec triage act,kspec item set,kspec batch). - Sanitization: Absent. No mention of content validation or sanitization before processing.
Audit Metadata