plan-build-verify

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes GitHub issue bodies and pull request comments to drive its automated workflows. This allows untrusted data to enter the agent context, potentially influencing its actions during build and verification steps. This risk is inherent to its collaborative purpose and is mitigated by mandatory human sign-off steps.
  • [COMMAND_EXECUTION]: The skill makes extensive use of the gh CLI tool and local shell environments to manage the software development lifecycle, including creating branches, issues, and running test suites.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the yahsan2/gh-sub-issue GitHub extension and uses npx to fetch additional skills from the author's repository.
  • [DYNAMIC_EXECUTION]: Python and Node.js scripts are executed to perform repository-wide link rewriting and to collect user acceptance evidence via the Chrome DevTools Protocol.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 02:36 PM
Security Audit — agent-trust-hub — plan-build-verify