byterover-ship
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a strict data access policy by explicitly instructing the agent to never read secrets, including
.envand credential files, during the curation process. - [SAFE]: Operational safety is ensured through human-in-the-loop requirements, specifically mandating that the user must be asked before a git tag is created.
- [SAFE]: The skill uses local CLI tools and standard git commands to perform its functions, ensuring that all data processing remains within the user's local development environment.
- [SAFE]: Project history and summaries are processed for the legitimate purpose of generating retrospectives, and the skill's instructions focus on specific, verifiable accomplishments rather than executing untrusted content extracted from those summaries.
Audit Metadata