campaign
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a robust governance framework for multi-pull-request orchestration. It explicitly separates advisory instructions from deterministic enforcement provided by project-owned commands and isolated authority.
- [SAFE]: Human-in-the-loop controls are strictly mandated for material decisions, irreversible actions, and merge authority, preventing autonomous high-risk operations.
- [SAFE]: The design incorporates 'Capability Preflights' to verify security mechanisms (such as isolated boundaries and resource envelopes) are active before dispatching work, demonstrating a defense-in-depth approach.
- [SAFE]: Although the skill processes external project data (governance, requirements, and PR comments), it mitigates indirect prompt injection risks by relying on external validation gates and human approval for state transitions.
Audit Metadata