auto-spec

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill uses Read, Grep, and Glob tools to analyze the repository for grounding requirements. It writes its output to the .ulpi/spec/ directory. All file system activity is scoped to the local project environment and is necessary for the skill's stated purpose of technical reconnaissance.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool for Phase 1 reconnaissance. The instructions indicate this is used to explore modules, data models, and interfaces. There is no evidence of arbitrary command execution or shell injection patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from user-provided feature requests and repository files. It includes a built-in adversarial critic loop (adversarial-verify) specifically designed to detect and fix ungrounded requirements or ambiguous instructions, providing a layer of defense against malicious or inaccurate inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 06:20 PM
Security Audit — agent-trust-hub — auto-spec