spec-miner

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified during the analysis. The skill's behavior aligns with its stated purpose of codebase documentation.
  • [PROMPT_INJECTION]: The instructions are strictly task-oriented and do not contain attempts to override agent behavior, bypass safety filters, or extract system prompts.
  • [COMMAND_EXECUTION]: While the skill utilizes the Bash tool, its application is limited to standard codebase exploration (e.g., using Glob and Grep). No high-risk commands, privilege escalation, or persistence mechanisms were found.
  • [DATA_EXFILTRATION]: There are no network-related commands or patterns suggesting the transmission of data to external servers. The skill operates locally on the provided codebase.
  • [EXTERNAL_DOWNLOADS]: The skill does not perform remote downloads or include unverifiable third-party dependencies. The only external link provided is for official documentation on a vendor-associated site.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 10:42 AM
Security Audit — agent-trust-hub — spec-miner