spec-merge-back

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified in the skill instructions. The skill defines a standard operating procedure (SOP) for document management.
  • [SAFE]: The skill includes defensive instructions ('Gates' and 'Red Flags') designed to prevent the AI agent from following improper user directions, such as guessing file paths or bypassing context gathering.
  • [SAFE]: File access is restricted to project-specific paths like .aidlc/project/ and {FEATURE_DIR}/implementation/plan.md. No access to sensitive system configurations or user credentials was detected.
  • [SAFE]: The use of internal tool calls like Get-SpecContext and using-aidlc is consistent with standard agent-based workflow orchestration and does not represent an external security threat.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 08:08 AM
Security Audit — agent-trust-hub — spec-merge-back