ask-questions-if-underspecified

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's instructions are focused on requirement clarification and follow safe interaction patterns. It limits the number of questions to avoid user fatigue and provides defaults to streamline the process.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to interact with local files in the .claude/context/memory/ directory for session persistence. These commands are restricted to the skill's own memory management and do not access sensitive user data or system files.
  • [PROMPT_INJECTION]: While the skill processes user-supplied requirements, it instructs the agent to respond with a specific, limited format (clarifying questions with defaults), which mitigates the potential for the agent to be diverted into unauthorized behaviors via indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 09:27 AM
Security Audit — agent-trust-hub — ask-questions-if-underspecified