pm-living-spec-consolidator
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary operations are restricted to reading and writing documentation files within the local project directory structure (specifically
docs/specs/anddocs/versions/). It does not request network access or execute shell commands. - [SAFE]: The skill depends on
nextstage-harness, which is a vendor-owned resource associated with the author 'nextstage-brasil'. - [SAFE]: While the skill processes potentially untrusted content from version requirements files (representing an indirect prompt injection surface), this behavior is the core functional requirement of the skill and is handled within a limited file-system scope. | Ingestion points: The skill reads from markdown files in the
{product_root}/docs/versions/directory. | Boundary markers: No explicit delimiters or instruction-bypass warnings are defined for the input content. | Capability inventory: Capabilities are limited to file system read and write operations on documentation files. | Sanitization: The skill maps source content to predefined markdown templates and sections, which limits the potential for executing instructions embedded in the data.
Audit Metadata