develop-story

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a sophisticated orchestrator for software development workflows, providing transparency through co-located implementation reports.
  • [COMMAND_EXECUTION]: Utilizes standard system utilities such as git, gh (GitHub CLI), jq, and awk to manage repository state and interact with project boards.
  • [EXTERNAL_DOWNLOADS]: Interacts with official APIs from GitHub, Bitbucket, and Jira (via Atlassian MCP). These interactions are restricted to well-known development services and are necessary for the skill's core functionality.
  • [SAFE]: Implements platform-specific hooks (PreCompact, Stop, PostToolUse) to handle context compaction and ensure the pipeline continues hands-free. These hooks are installed into the project's local configuration and point to scripts distributed with the skill.
  • [SAFE]: Employs 'Explore' sub-agents for specific read-only tasks like codebase mapping, tracker polling, and test failure triage, which improves context efficiency and reduces risk by isolating data processing.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:01 AM
Security Audit — agent-trust-hub — develop-story