skills/nweii/agent-stuff/spec-shaping/Gen Agent Trust Hub

spec-shaping

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is designed for product discovery and sprint planning, providing structured templates for specification documents and task registries. All operations are local to the project workspace.
  • [SAFE]: File system operations are restricted to searching, reading, and writing Markdown files in common project documentation directories (e.g., specs/, planning/).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided product plans and existing specification files, which constitutes a potential attack surface.
  • Ingestion points: Processes rough product ideas, technical concerns, and existing specification files in Interview Mode and Sprint Breakdown Mode.
  • Boundary markers: The instructions do not define explicit delimiters or 'ignore' warnings for the data being shaped.
  • Capability inventory: The skill's capabilities are limited to file system read/write operations for documentation purposes. It lacks network access, command execution, or dynamic code evaluation tools.
  • Sanitization: There is no explicit validation or escaping of the ingested product content. However, since the primary use case is content transformation for project planning, the risk is negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:24 AM