Everyone knows that the weak link is the specification. But this is a spurious argument, since, by definition, if you guarantee the implementation the only thing that's left exposed is the spec itself. At least you're reducing the attack surface
Also note that a specification can be input to other tools, such as a formal verification system for an encompassing system.