spec-first
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The workflow involves executing shell commands using development tools such as the GitHub CLI (
gh) for issue management andbunfor building, testing, and generating documentation. These actions are restricted to the local environment and the user's GitHub repository. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user descriptions of features or tasks to generate technical specifications and checklists. This represents a potential surface where adversarial input could influence the content of generated verification commands.
- Ingestion points: User feature requests and project descriptions are processed by the skill in
SKILL.md. - Boundary markers: The skill encourages the creation of durable, structured markdown artifacts to define constraints and requires manual confirmation before creating issues or executing plans.
- Capability inventory: The agent has the capability to write to the
.agents/memory/directory and execute shell commands via specific development tools. - Sanitization: The workflow relies on user confirmation checkpoints to review generated content before it is committed to GitHub or executed.
Audit Metadata