specsfy-roadmap-milestone-interviewer

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes specsfy milestones sync --project .. This is a standard operation for the 'Specsfy' toolset to synchronize project milestones and is consistent with the skill's stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests content from local files such as PROJECT.md, specs.md, and the specs/milestones/ directory.
  • Ingestion points: Files PROJECT.md, specs.md, and markdown files in the specs/milestones/ directory.
  • Boundary markers: The skill refers to a 'Contrato de perguntas numeradas' (Numbered questions contract) in .specsfy/Spec.md which likely defines interaction boundaries.
  • Capability inventory: The skill has the ability to execute the specsfy command-line tool.
  • Sanitization: None explicitly mentioned in the instructions, but the skill follows a rigid interview structure to minimize unintended instruction following.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 02:55 AM
Security Audit — agent-trust-hub — specsfy-roadmap-milestone-interviewer