doc-spec-audit
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted software specification (SPEC) artifacts, which creates a potential surface for malicious instructions embedded within the documents to influence the agent's behavior or audit results.
- Ingestion points: Specification files located in paths matching
docs/06_SPEC/SPEC-NN_*/...are read into the agent's context. - Boundary markers: The skill includes explicit instructions for the agent and its sub-agents to "Disregard the author self-assessment score" and ignore specific metadata fields (e.g.,
readiness_score,audit_score) within the artifact to prevent anchoring or manipulation. - Capability inventory: The skill possesses capabilities to create directories, write markdown and JSON reports to the
.aidoc/directory, execute bash commands for timing and state management, and dispatch specializedTasksub-agents. - Sanitization: Content from the untrusted specification artifacts is processed and passed to sub-agents without a dedicated sanitization or filtering layer.
- [COMMAND_EXECUTION]: The skill utilizes bash shell commands to manage its internal execution state, track performance, and organize project metadata.
- Evidence: Instructions are provided to use
mkdir -pfor directory creation anddate +%scombined with shell arithmetic to calculate elapsed time for break-circuit logic and status tracking.
Audit Metadata