speckit-check

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Executes the specify check command to verify the local development environment. This is a legitimate diagnostic function used to confirm that necessary tools are correctly installed and configured.
  • [EXTERNAL_DOWNLOADS]: Contains a reference to the github.com/github/spec-kit repository. This points to a well-known service and does not involve any automated downloads or executions from untrusted sources.
  • [INDIRECT_PROMPT_INJECTION]: The skill parses the output of the specify check command to provide user recommendations. While this involves processing external data, the skill lacks any dangerous capabilities (e.g., file system writes or network requests) that could be exploited via malicious tool output, and its scope is strictly diagnostic.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 01:46 AM
Security Audit — agent-trust-hub — speckit-check