monospec-kit

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill focuses on documentation and architectural planning. No evidence of credential harvesting, unauthorized file access, or persistence mechanisms was found. It follows best practices by organizing files within a dedicated 'documents/' directory.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes web search and webpage fetching to gather official documentation for technical dependencies (Step 3). This behavior is part of the core functionality for generating accurate technical specifications and does not involve downloading or executing binary payloads.
  • [PROMPT_INJECTION]: The skill is subject to an indirect prompt injection surface because it processes untrusted content from external documentation sites.
  • Ingestion points: Content retrieved from external websites via search and fetch tools (SKILL.md, Step 3).
  • Boundary markers: None; the skill does not explicitly use delimiters to separate researched documentation from its internal instructions.
  • Capability inventory: File system write access for generating Markdown files in the 'documents/' directory (SKILL.md, Step 5).
  • Sanitization: No explicit sanitization or filtering of external data is defined, relying instead on the agent's base safety protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 07:26 AM
Security Audit — agent-trust-hub — monospec-kit