co-change
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill facilitates specification management through the 'colony' MCP server and standard filesystem interactions. The logic is transparent and aligns with its stated purpose of assisting in development workflows.
- [COMMAND_EXECUTION]: The skill instructs the agent to traverse the directory structure to identify a repository root and to create new markdown files. These actions are performed within the local workspace and are appropriate for a developer-oriented tool.
- [INDIRECT_PROMPT_INJECTION]: The skill accepts user-provided descriptions and proposals, which are then passed to the
spec_change_opentool and written to the filesystem. While the instructions do not explicitly detail sanitization or the use of boundary markers for these inputs, this represents a typical surface for development tools and is considered a low risk within this execution environment.
Audit Metadata