spec-workflow

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted information from web searches during its research phase, creating a surface for indirect prompt injection that can affect later stages of the workflow.\n
  • Ingestion points: External web search results are used as primary input in the Research Phase (references/phase-transitions.md).\n
  • Boundary markers: The skill documentation does not define specific delimiters or instructions to ignore commands within ingested data.\n
  • Capability inventory: The agent possesses the capability to write files, perform git commits, and execute tasks autonomously (SKILL.md).\n
  • Sanitization: There is no indication that data from the research phase is sanitized or validated before influencing task generation.\n- [COMMAND_EXECUTION]: The implementation phase relies on an autonomous agent to execute tasks and modify the codebase. Users should monitor these operations as they are based on dynamically generated content.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 12:33 PM
Security Audit — agent-trust-hub — spec-workflow