skills/paleo/alignfirst/alspec/Gen Agent Trust Hub

alspec

Pass

Audited by Gen Agent Trust Hub on Mar 12, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill includes instructions that explicitly command the agent to disregard its own internal processing logic. Evidence: The file SKILL.md contains the instruction: 'Do not use your own plan mode.'
  • [PROMPT_INJECTION]: The skill mandates the execution of an external protocol, which could be used to introduce unverified instructions into the agent's context. Evidence: The file SKILL.md states: 'Mandatory: Execute the spec protocol from alignfirst.'
  • [PROMPT_INJECTION]: The skill ingests untrusted data (feature or task descriptions) without boundary markers or sanitization, creating a surface for indirect prompt injection. Ingestion points: Technical specification input described in SKILL.md. Boundary markers: Absent. Capability inventory: None (text generation only). Sanitization: Absent.
  • [NO_CODE]: The skill does not contain any executable scripts or configuration files, relying solely on natural language instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 12, 2026, 02:35 AM