best-practices-project-state

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell scripts (sanity.sh, sanity-live.sh) and Python scripts (validate_project_state.py) to automate the validation of generated Markdown reports.
  • Evidence: SKILL.md contains instructions to run bash scripts/sanity.sh and uv run --project . python scripts/validate_project_state.py.
  • Evidence: scripts/sanity-live.sh executes external skill entry points (e.g., brave-search/run.sh, github-search/run.sh) to verify the environment readiness.
  • [REMOTE_CODE_EXECUTION]: The skill invokes other internal tools/skills (browser-oracle, brave-search, github-search) but does not fetch or execute code from untrusted external URLs.
  • [DATA_EXFILTRATION]: While the skill uses search tools and external reviewers (WebGPT), these are part of the intended research workflow for generating project state reports and are not used for exfiltrating sensitive local data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — best-practices-project-state