requirements-author

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • Skill Content and Structure: The skill is composed of a collection of Markdown documents that define a structured lifecycle for authoring project requirements. It leverages templates and reference materials to guide an agent through Discover, Define, and Govern phases without the use of external scripts or binaries.
  • Industry Standard Alignment: The guidance provided is anchored in recognized professional standards such as ISO/IEC/IEEE 29148 for requirement characteristics, ISO/IEC 25010 for product quality, and NIST SP 800-160 for security engineering. These references are used appropriately to define quality rubrics and taxonomies.
  • Data Security and Privacy: No hardcoded credentials, sensitive file path access, or network exfiltration patterns were detected. The skill focuses on metadata and content structure for documentation rather than system-level operations.
  • Lack of Execution Patterns: The analysis found no evidence of remote code execution, obfuscation, or persistence mechanisms. The skill operates within the agent's standard file-reading capabilities to load its own instructional sections.
  • Indirect Prompt Injection Surface: The skill facilitates the processing of business context provided by users. However, it mitigates potential risks by enforcing strict structural requirements and quality checks (such as SMART and Atomicity checklists) which act as boundary markers for the generated content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 06:10 PM
Security Audit — agent-trust-hub — requirements-author