speckit-memory-md-audit

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains no malicious code, obfuscation, or unauthorized access patterns.\n- [PROMPT_INJECTION]: No evidence of direct prompt injection or instruction override was found. The skill processes local Markdown documentation files, which represents an indirect injection surface.\n
  • Ingestion points: Memory files (PROJECT_CONTEXT.md, ARCHITECTURE.md, DECISIONS.md, BUGS.md, WORKLOG.md in the .specify/ directory).\n
  • Boundary markers: Absent; instructions do not specify delimiters to separate the external content from the agent's internal instructions.\n
  • Capability inventory: None; the skill provides textual audit guidance and suggests changes without invoking executable tools or network operations.\n
  • Sanitization: Absent; the agent is directed to review the raw content of the provided files.\n- [DATA_EXFILTRATION]: No network activity or sensitive data access was identified. The skill's operations are confined to reviewing project-level documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 05:12 PM
Security Audit — agent-trust-hub — speckit-memory-md-audit