intent-driven-development
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows security best practices by including explicit instructions to avoid handling sensitive data. Operating Rule 8 mandates that real secrets, credentials, and PII must never be included in artifacts, requiring the use of redacted or synthetic values instead.
- [SAFE]: Protection against unauthorized destructive actions is built into the workflow. Operating Rule 9 prohibits running destructive tests, migrations, or operations against production data without explicit authorization.
- [SAFE]: The skill maintains project integrity by prohibiting unauthorized file modifications. Operating Rule 6 states the agent should not alter project files, create branches, or commit unless specifically requested by the user.
- [SAFE]: Context discovery (reading repository files and schemas) is used exclusively for technical fact-finding to support planning and does not involve the execution of external or untrusted code.
Audit Metadata