develop-task

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust development pipeline using standard version control and issue tracking tools. Operations are confined to the repository and official integration endpoints for GitHub and Jira.
  • [SAFE]: Local shell scripts such as advance-pipeline-lock.sh and install-hooks.sh are provided to manage pipeline state and register platform hooks (PreCompact, Stop, PostToolUse). These scripts follow best practices for idempotent and atomic operations.
  • [SAFE]: Data handling is restricted to the processing of task markdown files and the creation of pull requests and implementation reports. No evidence of unauthorized data exposure, exfiltration, or hardcoded credentials was found.
  • [SAFE]: The skill features strong context hygiene and recovery protocols, including a resume contract that verifies artifacts before continuing, which mitigates the risk of state corruption during long-running tasks.
  • [SAFE]: All external interactions target well-known and trusted developer services (GitHub, Atlassian/Jira) using official authentication methods.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:01 AM
Security Audit — agent-trust-hub — develop-task