ralph-specum-implement

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local files like tasks.md and .progress.md to define tasks for sub-agents. This presents a standard surface for indirect prompt injection common in coordination agents.
  • Ingestion points: Processes tasks.md and .progress.md (SKILL.md).
  • Boundary markers: No explicit boundary markers or delimiters are defined in the delegation logic.
  • Capability inventory: Limited to local file system operations on project-specific state files and delegating to the spec-executor sub-agent (SKILL.md).
  • Sanitization: The skill does not specify sanitization for the ingested task descriptions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 07:36 PM
Security Audit — agent-trust-hub — ralph-specum-implement