spec-to-code-compliance

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, potentially untrusted documentation and source code, which constitutes an indirect prompt injection surface.
  • Ingestion points: The skill ingests documentation and source code using the Read, Grep, and Glob tools specified in the allowed-tools section of SKILL.md.
  • Boundary markers: The resources/ANALYSIS_FORMAT.md file defines a structured output format that requires verbatim quotes and specific citations, providing a structural boundary between raw input data and the agent's analysis.
  • Capability inventory: The skill's capabilities include reading files, writing analysis reports to the local filesystem (spec-compliance/REPORT.md), and orchestrating sub-agents via the Workflow and Task tools as documented in SKILL.md.
  • Sanitization: The workflow explicitly includes a mitigation strategy where findings are sent to independent agents (refutation agents) that did not produce the original finding to verify the divergence, as described in the 'Do not check requirements in this context' section of SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 09:17 PM
Security Audit — agent-trust-hub — spec-to-code-compliance