implement-spec

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes specifications and task tickets which are external inputs, creating a vulnerability to indirect instructions.
  • Ingestion points: Technical specifications and implementation tickets are ingested in the first step of the process in SKILL.md.
  • Boundary markers: The skill lacks explicit delimiters or instructions to the agent to treat input data purely as data and not as command overrides.
  • Capability inventory: The skill possesses significant capabilities across its workflow, including subagent creation, writing files to locations outside the repository, and performing complex git operations such as branch merging and worktree management.
  • Sanitization: No data validation or sanitization process is described for the incoming specification content before it is passed to implementation subagents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 01:31 AM
Security Audit — agent-trust-hub — implement-spec