pk-track

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates exclusively on local project files within a controlled directory structure (.cockpit/). All file modifications are restricted to specific fields and follow a defined 'Snapshot Contract'.
  • [SAFE]: No unauthorized network operations, external downloads, or remote code executions are present. The skill relies on local logic and internal delegation to other trusted skills.
  • [SAFE]: The workflow includes a 'Quality Gate' phase to validate user-provided data and requires user confirmation before committing changes to files.
  • [SAFE]: The skill lacks any obfuscation, persistence mechanisms, or privilege escalation patterns. Instructions are clear, procedural, and aligned with its stated purpose of project tracking.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 07:34 AM
Security Audit — agent-trust-hub — pk-track