spec-product-demo

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill requires a validated execution context through a mandatory 'spec-context' step, ensuring the agent has correct local paths and metadata.
  • [SAFE]: It enforces a strict dependency on local files (prototype.md), preventing the agent from generating code based on hallucinated or placeholder requirements.
  • [SAFE]: Explicitly forbids the initialization of new frontend projects (e.g., Vite, Next.js) when a project root is missing, which mitigates risks related to unmanaged code or supply chain injection.
  • [SAFE]: No network access, remote code downloads, or credential harvesting patterns were detected in the instructions.
  • [SAFE]: The skill processes local prototype files as its primary source of truth (Ingestion: prototype.md, Boundary: absent, Capability: file-writing in prototypes/ folder, Sanitization: absent). It mitigates potential indirect prompt injection by restricting the agent's output to the defined page and interaction list.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 08:08 AM
Security Audit — agent-trust-hub — spec-product-demo