create-task

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to manage technical documentation and project tracking. All network operations are targeted at well-known services (GitHub, Jira, Bitbucket) through official APIs or CLI tools like 'gh'.
  • [SAFE]: Configuration and sensitive credentials (API tokens) are managed using standard environment variables and local '.env' files. This is the expected and safe method for local development tools.
  • [SAFE]: No instances of prompt injection, code obfuscation, or unauthorized data exfiltration were detected. The instructions maintain clear boundaries for the AI agent (e.g., prohibiting implementation work).
  • [SAFE]: Local shell execution is limited to benign repository maintenance and configuration tasks, such as creating directories, reading git history for context, and updating local status registries.
  • [SAFE]: The skill exhibits a low surface for indirect prompt injection. While it processes data from git logs and user input, it uses these only for populating documentation templates and includes formatting steps to maintain structural integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:02 AM
Security Audit — agent-trust-hub — create-task