governance

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes git subcommands to capture the repository context and status. The implementation uses a whitelist of safe subcommands and correctly employs the -- argument separator to prevent filenames from being interpreted as command-line flags.
  • [DATA_EXPOSURE]: The skill reads file metadata, including SHA-256 hashes and file sizes, to track the agent's progress. File access is restricted to the current repository or specific safe roots, preventing arbitrary file read across the system.
  • [SAFE]: The skill generates HTML reports that include task details and evidence logs. All interpolated strings are processed with html.escape() to ensure that the generated output is safe for human review in a browser.
  • [SAFE]: The skill uses uv for dependency management with pinned versions in uv.lock. It enforces strict path validation for its execution environment to prevent accidental or malicious environment contamination.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — governance