definition
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE]: The skill interacts with project-specific files located in
artefacts/and.github/. It reads architectural constraints and requirement documents, and updates a workflow state file (.github/pipeline-state.json). These actions are localized to the project repository and do not involve sensitive system files or credential harvesting. - [COMMAND_EXECUTION]: No patterns for shell command execution, subprocess spawning, or administrative privilege acquisition were detected.
- [EXTERNAL_DOWNLOADS]: The skill operates entirely on local project files and does not perform any network requests or external code downloads.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes content from various project files (discovery, metrics, and reference materials) to generate tasks, the risk is minimal as its capabilities are restricted to document generation within the project context. The processing of these documents is central to its primary purpose.
Audit Metadata