spec-orchestrator
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses forceful imperatives (e.g., "ABSOLUTELY MUST", "not negotiable", "DO NOT HAVE A CHOICE") and custom tags like
<EXTREMELY-IMPORTANT>to override the agent's standard decision-making process. While these patterns are common in adversarial prompt injections, here they are used as a meta-instruction to enforce process discipline and ensure the agent does not skip the defined software engineering lifecycle phases.- [DATA_EXFILTRATION]: No patterns for network operations (curl, wget, fetch) or access to sensitive credential files (.ssh, .aws, .env) were detected. The skill only references the creation of project-specific documentation in thedocs/specs/directory.- [COMMAND_EXECUTION]: The skill defines a routing table to other specialized skills (likespec-implement) but does not contain direct shell commands, subprocess calls, or scripts itself.
Audit Metadata