gathering-growth
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses local commands
git logandgh issue createto retrieve development context and manage task creation. These operations are aligned with the skill's stated purpose of content planning and execution. - [PROMPT_INJECTION]: Instructions are focused on workflow orchestration. No attempts to bypass safety filters or override agent behavior were detected.
- [DATA_EXFILTRATION]: No unauthorized network operations or exfiltration patterns were identified. Data movement is restricted to the agent context and local CLI tools.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from git logs which may contain untrusted input. However, the architecture enforces human review checkpoints after every processing phase (Scout, Plan, Draft, Polish), providing a strong control against accidental obedience to embedded instructions.
Audit Metadata