spec-driven-dev

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is entirely composed of documentation and instructional prompts that guide the AI agent's behavior during the software development lifecycle.
  • [NO_CODE]: There are no scripts, binaries, or executable code blocks associated with this skill. The examples provided are illustrative markdown templates for product requirements and technical specifications.
  • [EXTERNAL_DOWNLOADS]: No external URLs, package managers (npm, pip), or remote script execution patterns were found.
  • [DATA_EXFILTRATION]: There is no evidence of commands that access sensitive system files, environment variables, or network-bound exfiltration attempts.
  • [PROMPT_INJECTION]: The instructions use standard natural language to define an agent role ('specification architect') without attempting to bypass safety filters or ignore system constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 09:14 PM
Security Audit — agent-trust-hub — spec-driven-dev