spec-writer

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's functionality is strictly limited to text processing and documentation generation. It follows a structured methodology to produce markdown files without secondary side effects.
  • [COMMAND_EXECUTION]: No shell command execution or subprocess spawning was detected. The skill generates text content rather than executable scripts.
  • [EXTERNAL_DOWNLOADS]: The skill does not include any network operations, external dependency fetching, or remote script execution.
  • [DATA_EXFILTRATION]: There is no access to sensitive system paths, environment variables, or credentials. The file system access is restricted to reading and writing specification files (e.g., spec.md) within the project scope.
  • [PROMPT_INJECTION]: The instructions do not contain patterns intended to override agent behavior or bypass safety filters. The language is purely functional and focused on the stated goal of specification writing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 08:06 PM
Security Audit — agent-trust-hub — spec-writer