spec-kitty-plan
Pass
Audited by Gen Agent Trust Hub on Apr 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes git and spec-kitty CLI commands to manage the planning workflow and discover project features. These are standard operations for development automation tools.\n- [PROMPT_INJECTION]: The skill processes untrusted data from user input ($ARGUMENTS), FEATURE_SPEC, and constitution files (ingestion points). This surface lacks explicit boundary markers or sanitization, but the skill requires a mandatory 'interrogation' phase and user confirmation of the alignment summary before generating artifacts (capability: file-writes and CLI execution), mitigating risks from untrusted content.
Audit Metadata