spec-writer

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is designed for specification writing and follows a structured workflow that includes repository inspection and web research. No malicious code, obfuscation, or unauthorized data access patterns were detected.
  • [SAFE]: A manual confirmation step is enforced, requiring explicit user approval before the agent writes the SPECS.md file, which effectively mitigates risks associated with automated file system modifications.
  • [PROMPT_INJECTION]: The skill processes input from repository files and raw user ideas, creating a surface for indirect prompt injection. The analysis confirms: 1) Ingestion points: user requests and repository context; 2) Boundary markers: none; 3) Capability inventory: repository inspection, web research, and file writing; 4) Sanitization: mandatory human-in-the-loop approval step before writing files. The risk is minimized by this explicit control.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 01:07 PM
Security Audit — agent-trust-hub — spec-writer