spec-orchestrator

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses forceful imperatives (e.g., "ABSOLUTELY MUST", "not negotiable", "DO NOT HAVE A CHOICE") and custom tags like <EXTREMELY-IMPORTANT> to override the agent's standard decision-making process. While these patterns are common in adversarial prompt injections, here they are used as a meta-instruction to enforce process discipline and ensure the agent does not skip the defined software engineering lifecycle phases.- [DATA_EXFILTRATION]: No patterns for network operations (curl, wget, fetch) or access to sensitive credential files (.ssh, .aws, .env) were detected. The skill only references the creation of project-specific documentation in the docs/specs/ directory.- [COMMAND_EXECUTION]: The skill defines a routing table to other specialized skills (like spec-implement) but does not contain direct shell commands, subprocess calls, or scripts itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 08:00 AM