spec-workflow

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: No security issues were detected. The skill consists entirely of instructional markdown to guide the agent through a requirements and design process.
  • [NO_CODE]: The skill does not include any scripts, executable commands, or external package dependencies. It operates solely within the text-based planning phase.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of user-supplied requests into structured documentation. It includes security-positive instructions that explicitly forbid fetching remote resources and mandate user confirmation before transitioning between workflow phases, effectively mitigating common prompt injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — spec-workflow