skills/andiedie/skills/and-finish/Gen Agent Trust Hub

and-finish

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use Git, GitHub API, and vendor-specific tools like and-backend-contract to manage the lifecycle of delivery units. These operations are restricted to merging PRs and cleaning up related branches as part of the intended workflow.\n- [SAFE]: The skill reads the local configuration file .and/config.yml to resolve the backend contract and operational state, which is a standard procedure for this ecosystem.\n- [EXTERNAL_DOWNLOADS]: References to tools like and-implement, and-pack, and and-sweep are consistent with the 'Andiedie' vendor namespace and represent internal tool calls rather than downloads from untrusted sources.\n- [PROMPT_INJECTION]: The disable-model-invocation: true setting in the frontmatter provides a security boundary by preventing the model from executing tools in response to instructions found in the external review or receipt data it processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 02:31 AM
Security Audit — agent-trust-hub — and-finish