spec-kitty-agent

Pass

Audited by Gen Agent Trust Hub on Mar 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install spec-kitty-cli and gemini-agent via pip. These packages are functional requirements for the synchronization engine and the bridge architecture used to propagate configurations across agent environments. As spec-kitty-cli is associated with the vendor's primary skill purpose, it is documented as an expected dependency.\n- [COMMAND_EXECUTION]: The agent is required to run several local scripts, including sync_configuration.py and verify_workflow_state.py, for artifact management and phase verification. Furthermore, markdown templates for feature review and merging contain embedded Python code blocks that the agent executes to validate worktree locations and verify the integrity of research citations and source registers.\n- [PROMPT_INJECTION]: The skill employs a 'Project Ecosystem Constitution' and 'Anti-Simulation Rules' that use authoritative and imperative language to define the agent's persona and operational boundaries. These instructions mandate specific protocols, such as requiring explicit user confirmation ('Proceed', 'Go') for git operations and file writes, and strictly prohibiting the fabrication of tool outputs to ensure process transparency.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 12, 2026, 07:45 AM