and-finish
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use Git, GitHub API, and vendor-specific tools like
and-backend-contractto manage the lifecycle of delivery units. These operations are restricted to merging PRs and cleaning up related branches as part of the intended workflow.\n- [SAFE]: The skill reads the local configuration file.and/config.ymlto resolve the backend contract and operational state, which is a standard procedure for this ecosystem.\n- [EXTERNAL_DOWNLOADS]: References to tools likeand-implement,and-pack, andand-sweepare consistent with the 'Andiedie' vendor namespace and represent internal tool calls rather than downloads from untrusted sources.\n- [PROMPT_INJECTION]: Thedisable-model-invocation: truesetting in the frontmatter provides a security boundary by preventing the model from executing tools in response to instructions found in the external review or receipt data it processes.
Audit Metadata