speckit-review-types

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes a local bash script at .specify/scripts/bash/detect-changed-files.sh to determine which files require review. This is an expected functional component of the spec-kit framework.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes file contents identified by the change detection script. It lacks explicit boundary markers or sanitization for this ingested data, though its capabilities are primarily analytical, which limits the potential impact of such an injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 09:09 PM
Security Audit — agent-trust-hub — speckit-review-types