skills/sarthib7/agentsmith/spec/Gen Agent Trust Hub

spec

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues identified. The skill's operations are restricted to reading project files and writing to a specific markdown file within the local repository for documentation purposes.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes untrusted data from the repository (such as README or source code) to generate specification items. * Ingestion points: Reads repository files including README, package.json, source code, and tests in DISTILL and BACKPROP modes. * Boundary markers: Absent; the skill does not use specific delimiters to distinguish ingested file content from its own instructions. * Capability inventory: Reads repository files and writes to SPEC.md at the repo root. * Sanitization: Absent; content is processed directly to derive specification sections. This is considered safe as it is the primary intended function of the skill and relies on user review of the generated SPEC.md file.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 11:04 AM
Security Audit — agent-trust-hub — spec