run-retro

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates on a strictly evidence-backed workflow for analyzing project history (commits, PRs, logs). It explicitly forbids 'inventing a narrative' or speculating beyond available evidence.
  • [SAFE]: All significant mutations, such as documentation edits or ticket creation, require explicit user selection and confirmation during the 'grilling' (decision-making) phase.
  • [SAFE]: The skill delegates complex actions like issue implementation to other established workflows (implement-issue) rather than attempting to execute arbitrary code or unauthorized changes directly.
  • [SAFE]: The timing analysis reference establishes clear boundaries for data ingestion, emphasizing the use of stable identities and official platform standards (e.g., W3C Navigation Timing) rather than untrusted or obfuscated sources.
  • [SAFE]: The generated HTML report is stored in a predictable path (.agent/retrospectives/) and relies on a structured schema (render-html), minimizing the risk of arbitrary file writes or injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 11:59 PM
Security Audit — agent-trust-hub — run-retro