spec-conformance-audit

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill provides a structured methodology for auditing code against specifications. It focuses on traceability and verification without requesting dangerous capabilities.
  • [NO_CODE]: The skill consists entirely of markdown instructions and a YAML configuration for an agent interface. It contains no executable scripts, binaries, or command-line operations.
  • [INDIRECT_PROMPT_INJECTION]: As a tool that processes implementation evidence and requirement specifications, it has a surface for indirect prompt injection. However, it includes internal guidance to treat current behavior as evidence rather than contract and to prioritize user decisions, which mitigates simple override attempts. Severity is low and does not escalate the safe verdict.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 09:17 AM
Security Audit — agent-trust-hub — spec-conformance-audit