spec-implement
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's core logic is driven by external artifacts (design.md and plan.json) and conversation context. If these sources contain malicious instructions, they could influence the agent's behavior during implementation.
- Ingestion points: The skill reads
docs/specs/*/design.mdanddocs/specs/*/plan.jsonin the 'Prerequisites' and 'Step 1' sections. - Boundary markers: The skill includes a validation step where
plan.jsonis checked against a schema defined inspec-plan. - Capability inventory: The agent can write files, execute arbitrary tests/linters, perform git operations via
code-commit, and dispatch tasks tocode-subagents. - Sanitization: No explicit prompt sanitization or escaping mechanisms for the interpolated plan content are described.
- [COMMAND_EXECUTION]: The skill performs various system-level operations including running type checkers, linters, and language-specific test suites as part of the TDD workflow. It also manages git branches and worktrees.
- The execution of tests involves running potentially untrusted code generated by the agent based on the plan.
- The 'Subagent Mode' dispatches work to
code-subagents, extending the scope of execution.
Audit Metadata