product-spec-builder

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a documentation assistant. It uses a structured dialogue to collect requirements and populates a local template to generate a markdown file. No evidence of malicious intent or harmful operations was found.
  • [EXTERNAL_DOWNLOADS]: The skill references an external website (http://bananaslides.online/) as a resource for product design cases. This is a functional reference for the user and does not involve automated code execution or suspicious software downloads.
  • [DATA_EXFILTRATION]: No patterns of sensitive data access or exfiltration (such as accessing environment variables, SSH keys, or cloud credentials) were detected in the instructions or templates.
  • [COMMAND_EXECUTION]: The skill does not attempt to execute system commands, shell scripts, or binary files.
  • [PROMPT_INJECTION]: The persona-based instructions ('Feicai') are standard for role-playing agents and do not contain instructions to bypass safety filters or ignore system constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 08:43 AM
Security Audit — agent-trust-hub — product-spec-builder