spec-kitty-agent
Pass
Audited by Gen Agent Trust Hub on Mar 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install
spec-kitty-cliandgemini-agentviapip. These packages are functional requirements for the synchronization engine and the bridge architecture used to propagate configurations across agent environments. Asspec-kitty-cliis associated with the vendor's primary skill purpose, it is documented as an expected dependency.\n- [COMMAND_EXECUTION]: The agent is required to run several local scripts, includingsync_configuration.pyandverify_workflow_state.py, for artifact management and phase verification. Furthermore, markdown templates for feature review and merging contain embedded Python code blocks that the agent executes to validate worktree locations and verify the integrity of research citations and source registers.\n- [PROMPT_INJECTION]: The skill employs a 'Project Ecosystem Constitution' and 'Anti-Simulation Rules' that use authoritative and imperative language to define the agent's persona and operational boundaries. These instructions mandate specific protocols, such as requiring explicit user confirmation ('Proceed', 'Go') for git operations and file writes, and strictly prohibiting the fabrication of tool outputs to ensure process transparency.
Audit Metadata