specsfy-milestone-governor

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the specsfy CLI tool (specsfy milestones sync --project .) to synchronize milestone data. This is a vendor-provided command intended for the skill's core functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from local project files, including specs.md and files within the specs/milestones/ and specs/backlog/ directories.
  • Ingestion points: Files specs.md, specs/milestones/, and specs/backlog/ referenced in SKILL.md.
  • Boundary markers: Not explicitly defined in the prompt instructions for these files.
  • Capability inventory: Execution of specsfy milestones sync command.
  • Sanitization: Not specified, but the skill requires human confirmation before altering structural relations, which serves as a manual validation gate.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 02:55 AM
Security Audit — agent-trust-hub — specsfy-milestone-governor