matematic-spec-driven

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a methodology for creating project governance and planning documents (Constitution, Specification, Plan, and Tasks) within a local .matematic/ directory.
  • [COMMAND_EXECUTION]: The skill does not execute shell commands or subprocesses. Its operations are limited to reading, writing, and listing local files using the provided tools.
  • [EXTERNAL_DOWNLOADS]: No external packages or scripts are downloaded. While it references the github/spec-kit methodology as a source pattern, it does not attempt to fetch or install code from the internet.
  • [DATA_EXFILTRATION]: The skill is configured with data-residency: local and pii-egress: none. There are no network-capable tools or instructions to transmit data externally.
  • [PROMPT_INJECTION]: The instructions provide a clear operational framework without attempting to bypass safety filters, override system prompts, or extract sensitive internal instructions.
  • [METADATA_POISONING]: Metadata fields are used appropriately for versioning and authorship information related to the MateMatic internal development pipeline.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 08:27 AM
Security Audit — agent-trust-hub — matematic-spec-driven