spec-miner
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified during the analysis. The skill's behavior aligns with its stated purpose of codebase documentation.
- [PROMPT_INJECTION]: The instructions are strictly task-oriented and do not contain attempts to override agent behavior, bypass safety filters, or extract system prompts.
- [COMMAND_EXECUTION]: While the skill utilizes the Bash tool, its application is limited to standard codebase exploration (e.g., using Glob and Grep). No high-risk commands, privilege escalation, or persistence mechanisms were found.
- [DATA_EXFILTRATION]: There are no network-related commands or patterns suggesting the transmission of data to external servers. The skill operates locally on the provided codebase.
- [EXTERNAL_DOWNLOADS]: The skill does not perform remote downloads or include unverifiable third-party dependencies. The only external link provided is for official documentation on a vendor-associated site.
Audit Metadata