repo-quality-system-lifecycle
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill package contains governance documentation and evaluation cases without any executable code. No malicious patterns or safety bypass attempts were identified.\n- [EXTERNAL_DOWNLOADS]: The skill documentation includes an installation command using
npxto fetcharenukvern/skill_steward. This resource belongs to the skill author and is a legitimate part of the skill deployment process.\n- [INDIRECT_PROMPT_INJECTION]: The skill audits repository data such as documentation, plans, and schemas, which represents a potential attack surface for indirect prompt injection.\n - Ingestion points: The skill analyzes repository files including plans, specs, docs, maps, ADRs, FAQs, and schemas as described in SKILL.md.\n
- Boundary markers: No specific delimiters or safety instructions for handling untrusted data were identified.\n
- Capability inventory: The skill refers to using the
stewardCLI and standard repository validation commands (e.g.,pnpm run eval).\n - Sanitization: The skill instructions do not explicitly require sanitization or filtering of the external repository content it processes.
Audit Metadata