best-practices-one-shot
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a documentation and best-practices guide for orchestration. It does not contain executable code, obfuscation, or sensitive data access.
- [SAFE]: The 'Contract' section references an internal shell script (
skills/ask/run.sh) and standard file paths for output receipts (response.md,one-shot-verdict.json), which is consistent with its stated purpose of defining engineering standards. - [SAFE]: The skill promotes security-positive design patterns, such as 'Nonce-bound answers' to prevent the injection of stale or unauthorized artifacts into the agentic workflow.
Audit Metadata