plan-feature-scaffold

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is strictly limited to documentation management and planning tasks. Its instructions emphasize that it is for 'docs only' and must not change source code or dependencies.
  • [COMMAND_EXECUTION]: The skill references GitHub CLI and Git commands (e.g., gh pr create, git commit). These are included as literal instructional text to be written into generated task lists for later phases, not for execution by the skill itself.
  • [PROMPT_INJECTION]: The skill ingests existing feature specifications and templates to populate planning documents. This ingestion is controlled by a rigid schema and specific artifact scaling rules, which limits the potential impact of adversarial content in the input documents.
  • [DATA_EXFILTRATION]: Access is restricted to standard project files such as the feature documentation folder (docs/features/) and the roadmap. There is no evidence of the skill attempting to access sensitive environment variables, private keys, or system-level configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 05:30 PM
Security Audit — agent-trust-hub — plan-feature-scaffold