spec-workflow
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: No security issues were detected. The skill consists entirely of instructional markdown to guide the agent through a requirements and design process.
- [NO_CODE]: The skill does not include any scripts, executable commands, or external package dependencies. It operates solely within the text-based planning phase.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of user-supplied requests into structured documentation. It includes security-positive instructions that explicitly forbid fetching remote resources and mandate user confirmation before transitioning between workflow phases, effectively mitigating common prompt injection risks.
Audit Metadata