develop
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements strong security boundaries by instructing the agent to never hardcode credentials, secrets, or API keys, favoring environment variables or dedicated secret managers instead.
- [SAFE]: External network activity is limited to well-known and reputable services for UI development, such as Lorem Picsum, Pravatar, and DiceBear, which are used for generating placeholder assets.
- [SAFE]: The skill utilizes specialized, read-only subagents ('scout' and 'researcher') for exploration tasks, ensuring that environment discovery and external research cannot result in unauthorized file modifications or data exfiltration.
- [SAFE]: Command execution is restricted to standard development tools (Git, framework initializers like Next.js/Vite, and package managers like npm/pnpm) and is gated by freshness checks and user confirmation prompts to prevent conflicts or accidental overwrites in collaborative environments.
- [SAFE]: While the skill ingests external data from project specifications and scope files, it employs a structured 'Spec Gate' process and requires user interaction to validate critical architecture decisions before implementation.
Audit Metadata