research
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local validation script
node scripts/validate-project.mjsto ensure the repository is in a valid state before processing. - [COMMAND_EXECUTION]: Uses CLI tools like
npmandgh(GitHub CLI) to query package metadata and release information from official registries. - [EXTERNAL_DOWNLOADS]: Connects to established package registries and version control platforms, including npm, PyPI, crates.io, and GitHub, to retrieve live version data.
- [SAFE]: The skill ingests data from project backlog records and repository files to form research briefs for sub-agents. The process is constrained by strict formatting requirements and specific instructions that mitigate the risk of indirect prompt injection.
Audit Metadata