pm-living-spec-consolidator

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary operations are restricted to reading and writing documentation files within the local project directory structure (specifically docs/specs/ and docs/versions/). It does not request network access or execute shell commands.
  • [SAFE]: The skill depends on nextstage-harness, which is a vendor-owned resource associated with the author 'nextstage-brasil'.
  • [SAFE]: While the skill processes potentially untrusted content from version requirements files (representing an indirect prompt injection surface), this behavior is the core functional requirement of the skill and is handled within a limited file-system scope. | Ingestion points: The skill reads from markdown files in the {product_root}/docs/versions/ directory. | Boundary markers: No explicit delimiters or instruction-bypass warnings are defined for the input content. | Capability inventory: Capabilities are limited to file system read and write operations on documentation files. | Sanitization: The skill maps source content to predefined markdown templates and sections, which limits the potential for executing instructions embedded in the data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 08:18 PM
Security Audit — agent-trust-hub — pm-living-spec-consolidator