trellis-spec-bootstarp

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes repository source code and configuration files which could contain malicious instructions. Ingestion points: Repository source code, manifests, and workspace configs (references/repository-analysis.md). Boundary markers: None identified. Capability inventory: Shell command execution and file operations (references/mcp-setup.md, references/spec-writing.md). Sanitization: None identified.
  • [EXTERNAL_DOWNLOADS]: The skill fetches tools from external sources, including GitNexus via NPM and the ABCoder tool from the CloudWeGo repository on GitHub.
  • [REMOTE_CODE_EXECUTION]: The setup process executes code downloaded from external registries, specifically using 'go install' for ABCoder and 'npx' for GitNexus.
  • [COMMAND_EXECUTION]: The skill workflow involves executing shell commands to perform analysis and verify tool installations, such as 'npx gitnexus status' and 'abcoder parse'.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 08:46 AM