spec-implement

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's core logic is driven by external artifacts (design.md and plan.json) and conversation context. If these sources contain malicious instructions, they could influence the agent's behavior during implementation.
  • Ingestion points: The skill reads docs/specs/*/design.md and docs/specs/*/plan.json in the 'Prerequisites' and 'Step 1' sections.
  • Boundary markers: The skill includes a validation step where plan.json is checked against a schema defined in spec-plan.
  • Capability inventory: The agent can write files, execute arbitrary tests/linters, perform git operations via code-commit, and dispatch tasks to code-subagents.
  • Sanitization: No explicit prompt sanitization or escaping mechanisms for the interpolated plan content are described.
  • [COMMAND_EXECUTION]: The skill performs various system-level operations including running type checkers, linters, and language-specific test suites as part of the TDD workflow. It also manages git branches and worktrees.
  • The execution of tests involves running potentially untrusted code generated by the agent based on the plan.
  • The 'Subagent Mode' dispatches work to code-subagents, extending the scope of execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:54 AM
Security Audit — agent-trust-hub — spec-implement