best-practices-project-state
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell scripts (
sanity.sh,sanity-live.sh) and Python scripts (validate_project_state.py) to automate the validation of generated Markdown reports. - Evidence:
SKILL.mdcontains instructions to runbash scripts/sanity.shanduv run --project . python scripts/validate_project_state.py. - Evidence:
scripts/sanity-live.shexecutes external skill entry points (e.g.,brave-search/run.sh,github-search/run.sh) to verify the environment readiness. - [REMOTE_CODE_EXECUTION]: The skill invokes other internal tools/skills (browser-oracle, brave-search, github-search) but does not fetch or execute code from untrusted external URLs.
- [DATA_EXFILTRATION]: While the skill uses search tools and external reviewers (WebGPT), these are part of the intended research workflow for generating project state reports and are not used for exfiltrating sensitive local data.
Audit Metadata