spec-writer

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to read repository context and generate markdown documentation. This workflow is legitimate and confined to project management tasks within the local file system.
  • [SAFE]: No network operations, such as external downloads or data exfiltration, are present in the skill's instructions or associated scripts.
  • [SAFE]: The skill does not access sensitive system configuration files or credentials. All file operations are focused on documentation within the target repository.
  • [SAFE]: No obfuscation, hidden instructions, or encoded payloads were found in the SKILL.md or packaged export files.
  • [SAFE]: The prompt instructions do not contain patterns typical of prompt injection, such as attempts to ignore safety guidelines or override system constraints.
  • [SAFE]: Absolute file paths included in the README.md are metadata from the author's development environment and do not constitute a security risk to the end user.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 01:07 AM
Security Audit — agent-trust-hub — spec-writer