spec-test-execute

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized network operations were detected. The skill's behavior matches its stated purpose of generating test reports.
  • [DATA_EXPOSURE]: The skill reads local project context files such as product and technical memory to ensure report accuracy. This access is restricted to the local file system and is necessary for the reporting task.
  • [PROMPT_INJECTION]: The skill processes content from project documentation which presents a surface for indirect prompt injection.
  • Ingestion points: project/memory/product.md, project/memory/tech.md, project/memory/glossary.md, verification/test-plan.md, and verification/usecase.md.
  • Boundary markers: Absent.
  • Capability inventory: File reading and writing of Markdown reports to the project's verification directory.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 08:08 AM
Security Audit — agent-trust-hub — spec-test-execute