specsfy-progress

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Node.js scripts to parse repository data. It also references a CLI tool for installing specialists, but includes instructions requiring user authorization and prohibiting execution in sensitive workspace contexts.
  • [PROMPT_INJECTION]: The skill processes project data from markdown files. Ingestion points: Markdown files in the specs folder and specialists documentation. Boundary markers: None. Capability inventory: Local script execution and filesystem reading. Sanitization: Absent. The skill mitigates risks by enforcing a read-only interaction mode and directing the agent to ignore instructions embedded in documents.
  • [DATA_EXFILTRATION]: The skill accesses local project metadata and files. Analysis confirms that no sensitive files are targeted and no network capabilities are present to exfiltrate information.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 03:23 AM
Security Audit — agent-trust-hub — specsfy-progress