speckit-check
Pass
Audited by Gen Agent Trust Hub on May 16, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: Executes the
specify checkcommand to verify the local development environment. This is a legitimate diagnostic function used to confirm that necessary tools are correctly installed and configured. - [EXTERNAL_DOWNLOADS]: Contains a reference to the
github.com/github/spec-kitrepository. This points to a well-known service and does not involve any automated downloads or executions from untrusted sources. - [INDIRECT_PROMPT_INJECTION]: The skill parses the output of the
specify checkcommand to provide user recommendations. While this involves processing external data, the skill lacks any dangerous capabilities (e.g., file system writes or network requests) that could be exploited via malicious tool output, and its scope is strictly diagnostic.
Audit Metadata