specsfy-progress
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Node.js scripts to parse repository data. It also references a CLI tool for installing specialists, but includes instructions requiring user authorization and prohibiting execution in sensitive workspace contexts.
- [PROMPT_INJECTION]: The skill processes project data from markdown files. Ingestion points: Markdown files in the specs folder and specialists documentation. Boundary markers: None. Capability inventory: Local script execution and filesystem reading. Sanitization: Absent. The skill mitigates risks by enforcing a read-only interaction mode and directing the agent to ignore instructions embedded in documents.
- [DATA_EXFILTRATION]: The skill accesses local project metadata and files. Analysis confirms that no sensitive files are targeted and no network capabilities are present to exfiltrate information.
Audit Metadata