skills/shipshitdev/skills/spec-first/Gen Agent Trust Hub

spec-first

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The workflow involves executing shell commands using development tools such as the GitHub CLI (gh) for issue management and bun for building, testing, and generating documentation. These actions are restricted to the local environment and the user's GitHub repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user descriptions of features or tasks to generate technical specifications and checklists. This represents a potential surface where adversarial input could influence the content of generated verification commands.
  • Ingestion points: User feature requests and project descriptions are processed by the skill in SKILL.md.
  • Boundary markers: The skill encourages the creation of durable, structured markdown artifacts to define constraints and requires manual confirmation before creating issues or executing plans.
  • Capability inventory: The agent has the capability to write to the .agents/memory/ directory and execute shell commands via specific development tools.
  • Sanitization: The workflow relies on user confirmation checkpoints to review generated content before it is committed to GitHub or executed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — spec-first