develop-task
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a robust development pipeline using standard version control and issue tracking tools. Operations are confined to the repository and official integration endpoints for GitHub and Jira.
- [SAFE]: Local shell scripts such as
advance-pipeline-lock.shandinstall-hooks.share provided to manage pipeline state and register platform hooks (PreCompact, Stop, PostToolUse). These scripts follow best practices for idempotent and atomic operations. - [SAFE]: Data handling is restricted to the processing of task markdown files and the creation of pull requests and implementation reports. No evidence of unauthorized data exposure, exfiltration, or hardcoded credentials was found.
- [SAFE]: The skill features strong context hygiene and recovery protocols, including a resume contract that verifies artifacts before continuing, which mitigates the risk of state corruption during long-running tasks.
- [SAFE]: All external interactions target well-known and trusted developer services (GitHub, Atlassian/Jira) using official authentication methods.
Audit Metadata