sf-tech-design

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local utility and maintenance scripts using node (e.g., instructions.mjs, create-artifact.mjs, artifact-quality.mjs). These scripts are located within the host project's .specforge/core/scripts/ directory and are part of the intended workflow for artifact management and quality assurance.
  • [SAFE]: No patterns of data exfiltration, credential harvesting, or unauthorized network access were found. The skill operates on local project files to translate requirements into design documents.
  • [SAFE]: External references are limited to reputable architectural and documentation resources (such as AWS, Microsoft Azure, GOV.UK, and arc42), which are utilized strictly for guidance and best practices.
  • [SAFE]: The skill incorporates human-in-the-loop safeguards by requiring explicit user confirmation for technical decisions and dependency changes before proceeding with automated tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 02:20 AM
Security Audit — agent-trust-hub — sf-tech-design