spec-writer
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is designed for specification writing and follows a structured workflow that includes repository inspection and web research. No malicious code, obfuscation, or unauthorized data access patterns were detected.
- [SAFE]: A manual confirmation step is enforced, requiring explicit user approval before the agent writes the
SPECS.mdfile, which effectively mitigates risks associated with automated file system modifications. - [PROMPT_INJECTION]: The skill processes input from repository files and raw user ideas, creating a surface for indirect prompt injection. The analysis confirms: 1) Ingestion points: user requests and repository context; 2) Boundary markers: none; 3) Capability inventory: repository inspection, web research, and file writing; 4) Sanitization: mandatory human-in-the-loop approval step before writing files. The risk is minimized by this explicit control.
Audit Metadata