user-story-acceptance-manifest

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a read-only workflow for project management documentation. It lacks capabilities to perform system modifications or network requests to untrusted domains.
  • [PROMPT_INJECTION]: Instructions contain negative constraints ("Do not edit code", "Do not create branches") that reinforce its specific documentation-only scope, with no evidence of bypass or override patterns.
  • [DATA_EXFILTRATION]: While the skill references external resources like GitHub issues and design documents, it does so to populate a markdown template. There are no hardcoded credentials or unauthorized network operations detected.
  • [REMOTE_CODE_EXECUTION]: No remote script downloads or dynamic code execution patterns are present. The "verification command" field in the manifest is informational and not executed by the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 01:16 AM
Security Audit — agent-trust-hub — user-story-acceptance-manifest