quick-spec

Pass

Audited by Gen Agent Trust Hub on Mar 22, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: This skill interacts with user-provided data and existing codebase files to generate plans, creating a surface for indirect instructions.\n- Ingestion points: User requests in Step 1 and source code files analyzed in Step 2.\n- Boundary markers: The skill does not use specific delimiters to isolate external content.\n- Capability inventory: The workflow involves reading files and writing technical specifications to the local artifacts directory.\n- Sanitization: No content sanitization or validation is implemented for ingested data.\n- [COMMAND_EXECUTION]: The skill manages state and documentation by creating and renaming technical specification files on the local filesystem using platform-provided variables.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 22, 2026, 04:37 PM