specrail-implement

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized external communications were detected. All activities are confined to the local repository environment.
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (checks/route_gate.py and checks/check_workflow.py) to verify task readiness and workflow integrity. These are standard development tools and parameters.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by reading external documentation.
  • Ingestion points: Data is read from linked issues, product specs, tech specs, and task plans.
  • Boundary markers: Explicitly includes a 'Boundaries' section that prohibits final approvals, unauthorized merges, and secret publication.
  • Capability inventory: The skill has the capability to execute local Python scripts.
  • Sanitization: Relies on operational boundaries and human-in-the-loop review rather than automated sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 09:48 AM
Security Audit — agent-trust-hub — specrail-implement