specgate-work-preparation

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the 'specgate' command-line interface to manage the artifact lifecycle, executing commands like 'specgate work create-quick', 'specgate artifact publish', and 'specgate gates check'.\n- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it reads and processes external documents to generate work contracts.\n
  • Ingestion points: The instructions in SKILL.md direct the agent to read requests, repository instructions, and source documents.\n
  • Boundary markers: There are no explicit instructions for using delimiters or specific prompts to ignore instructions within the ingested data.\n
  • Capability inventory: The agent can execute shell commands via the 'specgate' utility and write files to the local '.specgate/work' directory.\n
  • Sanitization: The skill requires the agent to present all extracted data and previews to the human user for explicit approval before executing any state-altering commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 03:18 PM
Security Audit — agent-trust-hub — specgate-work-preparation