spec-orchestrator
Pass
Audited by Gen Agent Trust Hub on May 29, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill employs strong imperative language, such as "ABSOLUTELY MUST", "not negotiable", and "not optional", to mandate the invocation of other skills. While this style of language is sometimes associated with instruction overrides, here it is used exclusively to maintain workflow consistency and does not attempt to bypass safety filters or reveal system prompts.
- [DATA_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or unauthorized network operations were detected. The skill focuses on managing documentation artifacts within the project directory.
- [REMOTE_CODE_EXECUTION]: The skill does not contain any patterns for downloading or executing remote code. It orchestrates local tasks and skills.
- [COMMAND_EXECUTION]: While the skill defines a workflow for implementation, it does not directly invoke shell commands or provide mechanisms for arbitrary command injection.
Audit Metadata