aip-user-stories

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill operates within a restricted environment, only accessing trusted domains and executing specific GitHub CLI commands. No malicious behavior, data exfiltration, or obfuscation was identified.\n- [EXTERNAL_DOWNLOADS]: Fetches AIP content from cwiki.apache.org and pull request information from github.com. Both sources are recognized as well-known and trusted for the skill's specific purpose of analyzing official Apache Airflow proposals.\n- [COMMAND_EXECUTION]: Utilizes the GitHub CLI (gh) to view PR details and diffs. Tool access is strictly constrained in the skill frontmatter to the view and diff subcommands, which minimizes the risk of arbitrary command execution and aligns with the principle of least privilege.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 09:43 PM
Security Audit — agent-trust-hub — aip-user-stories