speckit-orchestrator

Pass

Audited by Gen Agent Trust Hub on Mar 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through the ingestion of user-controlled repository artifacts.\n- Ingestion points: The orchestrator reads and interprets content from spec.md, plan.md, tasks.md, and .specify/memory/constitution.md during workflow phases.\n- Boundary markers: The skill lacks explicit delimiters or instructions to isolate user-provided text from agent instructions within these artifacts.\n- Capability inventory: It orchestrates high-capability implementation skills such as superpowers:executing-plans and coordinates the execution of local automation scripts.\n- Sanitization: There is no evidence of content sanitization or instruction filtering in the orchestration modules to prevent malicious instructions embedded in artifacts from being followed.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 5, 2026, 07:12 PM