alspec
Pass
Audited by Gen Agent Trust Hub on Mar 12, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill includes instructions that explicitly command the agent to disregard its own internal processing logic. Evidence: The file
SKILL.mdcontains the instruction: 'Do not use your own plan mode.' - [PROMPT_INJECTION]: The skill mandates the execution of an external protocol, which could be used to introduce unverified instructions into the agent's context. Evidence: The file
SKILL.mdstates: 'Mandatory: Execute the spec protocol from alignfirst.' - [PROMPT_INJECTION]: The skill ingests untrusted data (feature or task descriptions) without boundary markers or sanitization, creating a surface for indirect prompt injection. Ingestion points: Technical specification input described in
SKILL.md. Boundary markers: Absent. Capability inventory: None (text generation only). Sanitization: Absent. - [NO_CODE]: The skill does not contain any executable scripts or configuration files, relying solely on natural language instructions.
Audit Metadata