specification-executor

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists exclusively of markdown instructions, JSON evaluation files, and reference templates. It does not ship any scripts, binaries, or active code components, eliminating the risk of direct remote code execution or persistence.
  • [COMMAND_EXECUTION]: The skill utilizes official workspace tools for Notion interaction (search, fetch, create, update). These tools operate within the user's workspace context and follow a defined sequence (Find -> Fetch -> Parse -> Plan -> Execute) that maintains human-readable project state.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted data from Notion specification pages via Notion:notion-fetch (documented in SKILL.md and reference/spec-parsing.md). It mitigates this risk by providing specific parsing guidelines and structured implementation templates (e.g., reference/standard-implementation-plan.md) that act as logical boundaries. Its capabilities are limited to Notion document management (Notion:notion-create-pages, Notion:notion-update-page), and the workflow emphasizes human review and clear acceptance criteria as final validation steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:59 PM
Security Audit — agent-trust-hub — specification-executor