doc-spec-audit

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted software specification (SPEC) artifacts, which creates a potential surface for malicious instructions embedded within the documents to influence the agent's behavior or audit results.
  • Ingestion points: Specification files located in paths matching docs/06_SPEC/SPEC-NN_*/... are read into the agent's context.
  • Boundary markers: The skill includes explicit instructions for the agent and its sub-agents to "Disregard the author self-assessment score" and ignore specific metadata fields (e.g., readiness_score, audit_score) within the artifact to prevent anchoring or manipulation.
  • Capability inventory: The skill possesses capabilities to create directories, write markdown and JSON reports to the .aidoc/ directory, execute bash commands for timing and state management, and dispatch specialized Task sub-agents.
  • Sanitization: Content from the untrusted specification artifacts is processed and passed to sub-agents without a dedicated sanitization or filtering layer.
  • [COMMAND_EXECUTION]: The skill utilizes bash shell commands to manage its internal execution state, track performance, and organize project metadata.
  • Evidence: Instructions are provided to use mkdir -p for directory creation and date +%s combined with shell arithmetic to calculate elapsed time for break-circuit logic and status tracking.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:18 PM
Security Audit — agent-trust-hub — doc-spec-audit