onenote-local-dev-loop
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill mandates the use of synthetic fixtures and an isolated sandbox, explicitly prohibiting production credentials or notebook content from being used in local development.- [SAFE]: It implements a production-target guard and 'fail closed' error handling to prevent accidental live actions when environment bindings are missing.- [SAFE]: External resource links are restricted to official Microsoft Graph documentation on trusted domains.- [SAFE]: The instructions include security best practices such as secret canary usage and scanning artifacts for production identifiers before preservation.
Audit Metadata