review-extraction
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/build_golden_slice_bundle.pyusessubprocess.run()to executegit diffandgit --no-index. This is used exclusively for generating code diffs for the 'optional_code' review bundle when tooling changes, which is a standard development workflow within this skill's context. - [SAFE]: The skill implements a robust 'refusal contract' for sign-offs. In
scripts/build_golden_slice_bundle.py, the_signoff_refusal_reasonsfunction enforces deterministic quality gates, refusing to generate closure artifacts if extraction results do not perfectly match human-labeled ground truth or contain unresolved blockers. - [SAFE]: The skill explicitly defines 'Non-goals' in
SKILL.md, prohibiting the agent from mutating core extractor code, document presets, or promotional ledgers during the evidence gathering phase. This enforces a clear separation between observation and mutation. - [SAFE]: The script
scripts/build_golden_slice_bundle.pyperforms local file system operations (shutil, Path) and PDF processing (pypdfium2) within a specified output directory, adhering to the principle of least privilege for the intended task of artifact generation.
Audit Metadata