spec-miner

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill instructions and reference materials guide the agent to locate and read sensitive configuration data, specifically targeting .env files and environment variable usage patterns such as os.environ and ConfigService (SKILL.md, references/analysis-checklist.md, references/analysis-process.md).
  • [EXTERNAL_DOWNLOADS]: The skill provides a link to external documentation on jeffallan.github.io which is currently flagged as blacklisted by automated security scanners (SKILL.md).
  • [COMMAND_EXECUTION]: The skill incorporates the Bash tool into its allowed toolkit to perform technical exploration and analysis of user-provided codebases (SKILL.md).
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted codebases and possesses high-privilege tool access. It lacks explicit security controls for this data ingestion:
  • Ingestion points: Uses Read, Grep, and Glob to process files in a project directory (SKILL.md, references/analysis-process.md).
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are provided.
  • Capability inventory: Possesses Bash tool access (SKILL.md).
  • Sanitization: No input validation or content filtering is specified before external data enters the agent context.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 01:20 PM
Security Audit — agent-trust-hub — spec-miner