kspec-triage

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from an "inbox" and "observations" which may contain malicious instructions designed to influence the agent's actions (Indirect Prompt Injection).
  • Ingestion points: Data enters the context via kspec inbox list (referenced in SKILL.md and docs/inbox.md) and kspec meta observations (referenced in docs/observations.md).
  • Boundary markers: While explicit text-based delimiters are not used, the "Record → Act" pattern serves as a functional boundary by separating data ingestion from command execution.
  • Capability inventory: The agent can execute impactful actions through kspec triage act and kspec batch across all provided files.
  • Sanitization: The workflow relies on the agent's evaluation and the recording of reasoning before execution to ensure intended behavior.
  • [COMMAND_EXECUTION]: The skill uses the kspec CLI tool to perform all operations, which is the intended functional method for this skill.
  • Evidence: All primary workflow steps in SKILL.md and documentation files use tool calls like kspec triage record, kspec task set, and kspec batch to manage state and execute tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 04:49 PM
Security Audit — agent-trust-hub — kspec-triage