specsfy-interviewer
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
specsfy effortcommand to update specification metadata including effort scores and justifications. This is a local command execution pattern integrated into the vendor's specialized workflow for project management.- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from externalspec.mdfiles. This represents an indirect prompt injection surface where untrusted content in the specification files could potentially influence the agent's instructions. The skill includes a 'Contrato de perguntas numeradas' interaction protocol to define boundaries for processing this content.
Audit Metadata