user-story-acceptance-manifest
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a read-only workflow for project management documentation. It lacks capabilities to perform system modifications or network requests to untrusted domains.
- [PROMPT_INJECTION]: Instructions contain negative constraints ("Do not edit code", "Do not create branches") that reinforce its specific documentation-only scope, with no evidence of bypass or override patterns.
- [DATA_EXFILTRATION]: While the skill references external resources like GitHub issues and design documents, it does so to populate a markdown template. There are no hardcoded credentials or unauthorized network operations detected.
- [REMOTE_CODE_EXECUTION]: No remote script downloads or dynamic code execution patterns are present. The "verification command" field in the manifest is informational and not executed by the skill itself.
Audit Metadata