ns-living-spec

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is focused on technical documentation maintenance. It implements safety checks by requiring explicit approval markers ('Code Review: Approved') before executing versioned updates and uses 'read before write' patterns to ensure existing content is preserved or intentionally updated.\n- [INDIRECT_PROMPT_INJECTION]: The skill acts as a data sink for external inputs such as task descriptions and requirements.\n
  • Ingestion points: Processes requirements.md, execution-handoff.md, task descriptions, and git diff outputs as sources for documentation.\n
  • Boundary markers: The instructions do not define specific delimiter boundaries for external data ingestion.\n
  • Capability inventory: Limited to reading and writing markdown files in the local docs/specs/ directory; no network access or system command execution capabilities are identified.\n
  • Sanitization: None; relies on the agent to properly format requirements into SHALL-based markdown blocks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:15 PM
Security Audit — agent-trust-hub — ns-living-spec