spec-kitty-plan

Pass

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes git and spec-kitty CLI commands to manage the planning workflow and discover project features. These are standard operations for development automation tools.\n- [PROMPT_INJECTION]: The skill processes untrusted data from user input ($ARGUMENTS), FEATURE_SPEC, and constitution files (ingestion points). This surface lacks explicit boundary markers or sanitization, but the skill requires a mandatory 'interrogation' phase and user confirmation of the alignment summary before generating artifacts (capability: file-writes and CLI execution), mitigating risks from untrusted content.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 3, 2026, 06:09 PM