governance
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes
gitsubcommands to capture the repository context and status. The implementation uses a whitelist of safe subcommands and correctly employs the--argument separator to prevent filenames from being interpreted as command-line flags. - [DATA_EXPOSURE]: The skill reads file metadata, including SHA-256 hashes and file sizes, to track the agent's progress. File access is restricted to the current repository or specific safe roots, preventing arbitrary file read across the system.
- [SAFE]: The skill generates HTML reports that include task details and evidence logs. All interpolated strings are processed with
html.escape()to ensure that the generated output is safe for human review in a browser. - [SAFE]: The skill uses
uvfor dependency management with pinned versions inuv.lock. It enforces strict path validation for its execution environment to prevent accidental or malicious environment contamination.
Audit Metadata