om-spec-writing

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill proactively addresses the risk of processing untrusted repository content such as issues, PR bodies, and documentation. It instructs the agent to treat this content strictly as data, refuse any embedded instructions, and report suspected injection attempts.
  • [DATA_EXFILTRATION]: The instructions include a 'Secrets Hygiene' policy that forbids pasting or processing credentials, tokens, or environment variables. It further restricts operations to the local repository and its tracker, preventing data leakage to external sources.
  • [PROMPT_INJECTION]: A static detector signal for 'ignore previous instructions' was identified as a false positive. The phrase is used within a defensive instruction that warns the agent to identify and ignore such patterns if encountered in external data inputs.
  • [COMMAND_EXECUTION]: The skill restricts command execution to in-scope tasks related to building or testing the project and explicitly prohibits any operations that would exfiltrate data or access state outside the controlled repository environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 12:20 AM
Security Audit — agent-trust-hub — om-spec-writing