spec-design-research
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows standard documentation and research procedures. It primarily involves reading local project design files (e.g., solution.md, prd.md) and generating a research report (research.md). No unauthorized network access, credential handling, or code execution patterns were found.
- [DATA_EXPOSURE]: While the skill reads project-level documents like
project/memory/*andproject/contracts/, these are scoped to the project's design context and are used solely to generate internal research documentation. No exfiltration patterns were detected. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from project files (requirements and solutions). While it lacks explicit boundary markers or sanitization for this content, its capabilities are restricted to document generation and internal tool routing, presenting a negligible risk profile.
Audit Metadata