specsfy-specialist-design-system

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the local project environment, which could be exploited to influence agent behavior if the files are maliciously crafted.\n
  • Ingestion points: The skill processes DESIGNSYSTEM.MD, INTERFACE.md, .specsfy/STACK.md, manifests, and route definitions from the consumer project.\n
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are defined for the ingested files.\n
  • Capability inventory: The skill is authorized to update DESIGNSYSTEM.MD and instructs the agent to execute a local validation script.\n
  • Sanitization: No input validation or content filtering is specified for the ingested project files.\n- [COMMAND_EXECUTION]: The skill requires the execution of a local validation script (quick_validate.py) and the monorepo's test suite to verify changes. This is a standard validation procedure for the tool's intended environment.\n- [EXTERNAL_DOWNLOADS]: The skill references documentation and standards from authoritative external domains for design guidance.\n
  • Evidence: Includes links to Google's Material Design, IBM's Carbon Design System, GOV.UK, and W3C documentation in the standards reference file.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 10:21 PM
Security Audit — agent-trust-hub — specsfy-specialist-design-system