specs-data

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes multiple external project files which could contain hidden instructions designed to influence the agent's analysis or output contents.\n
  • Ingestion points: Technical specification files are read from docs/specs/API/, docs/specs/data/, docs/specs/ws/, docs/specs/grpc/, and docs/specs/task-UCS/.\n
  • Boundary markers: The instructions do not specify the use of delimiters or provide instructions to the model to ignore any embedded directives within the specification files being processed.\n
  • Capability inventory: The skill is capable of performing file-write operations to docs/specs/data/struct.md based on its analysis of external content.\n
  • Sanitization: There is no mechanism described for sanitizing or validating the contents of the specification files before they are summarized and integrated into the final document.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 02:49 PM
Security Audit — agent-trust-hub — specs-data