kspec-triage
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from an "inbox" and "observations" which may contain malicious instructions designed to influence the agent's actions (Indirect Prompt Injection).
- Ingestion points: Data enters the context via
kspec inbox list(referenced inSKILL.mdanddocs/inbox.md) andkspec meta observations(referenced indocs/observations.md). - Boundary markers: While explicit text-based delimiters are not used, the "Record → Act" pattern serves as a functional boundary by separating data ingestion from command execution.
- Capability inventory: The agent can execute impactful actions through
kspec triage actandkspec batchacross all provided files. - Sanitization: The workflow relies on the agent's evaluation and the recording of reasoning before execution to ensure intended behavior.
- [COMMAND_EXECUTION]: The skill uses the
kspecCLI tool to perform all operations, which is the intended functional method for this skill. - Evidence: All primary workflow steps in
SKILL.mdand documentation files use tool calls likekspec triage record,kspec task set, andkspec batchto manage state and execute tasks.
Audit Metadata