spec-critique
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external specification and requirement documents that may contain untrusted content. It lacks boundary markers or delimiters to isolate these inputs from its core instructions, creating a surface where instructions embedded in the data could be interpreted and executed by the agent.
- Ingestion points: Phase 1 in SKILL.md instructs the agent to read files from
.claude/context/specs/and.claude/context/requirements/using shell commands. - Boundary markers: The workflow does not specify the use of delimiters, such as XML tags or special markers, to wrap the content of the specifications or requirements to distinguish data from instructions.
- Capability inventory: The skill is granted
Read,Write,Edit,Glob, andGreptools, providing it with the ability to modify project files based on its analysis of the ingested content. - Sanitization: There is no mention of sanitizing or validating the input data before it is processed by the agent's extended thinking phase.
Audit Metadata