spec-product-demo
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill requires a validated execution context through a mandatory 'spec-context' step, ensuring the agent has correct local paths and metadata.
- [SAFE]: It enforces a strict dependency on local files (prototype.md), preventing the agent from generating code based on hallucinated or placeholder requirements.
- [SAFE]: Explicitly forbids the initialization of new frontend projects (e.g., Vite, Next.js) when a project root is missing, which mitigates risks related to unmanaged code or supply chain injection.
- [SAFE]: No network access, remote code downloads, or credential harvesting patterns were detected in the instructions.
- [SAFE]: The skill processes local prototype files as its primary source of truth (Ingestion: prototype.md, Boundary: absent, Capability: file-writing in prototypes/ folder, Sanitization: absent). It mitigates potential indirect prompt injection by restricting the agent's output to the defined page and interaction list.
Audit Metadata