speckit-bugfix

Pass

Audited by Gen Agent Trust Hub on Mar 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local bash script at '.specify/scripts/bash/create-bugfix.sh' to initialize the workflow. This is a core capability intended for the spec-kit project structure.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface when processing user-provided bug descriptions. Ingestion points: User input is ingested via the '$ARGUMENTS' variable in SKILL.md. Boundary markers: Absent; the input is interpolated into the prompt without delimiters or 'ignore' instructions. Capability inventory: The agent can execute a specific local shell script and perform file-write operations. Sanitization: None; the agent is directed to parse raw user text directly into a markdown template.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 13, 2026, 06:47 PM