spec-critique

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external specification and requirement documents that may contain untrusted content. It lacks boundary markers or delimiters to isolate these inputs from its core instructions, creating a surface where instructions embedded in the data could be interpreted and executed by the agent.
  • Ingestion points: Phase 1 in SKILL.md instructs the agent to read files from .claude/context/specs/ and .claude/context/requirements/ using shell commands.
  • Boundary markers: The workflow does not specify the use of delimiters, such as XML tags or special markers, to wrap the content of the specifications or requirements to distinguish data from instructions.
  • Capability inventory: The skill is granted Read, Write, Edit, Glob, and Grep tools, providing it with the ability to modify project files based on its analysis of the ingested content.
  • Sanitization: There is no mention of sanitizing or validating the input data before it is processed by the agent's extended thinking phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 03:28 AM
Security Audit — agent-trust-hub — spec-critique