workflow-feature-flag
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a structured workflow for feature flag management, including detection, design, implementation, and cleanup phases, all following industry standard practices.- [DATA_EXPOSURE]: Sensitive information such as API keys and organization identifiers are handled using placeholders (e.g., , <PROJECT_ID>) and environment variable references, which is a safe practice.- [SAFE]: External tool integrations, specifically the use of Sentry for issue analysis and Supabase for log retrieval, are restricted to monitoring performance and error rates during rollouts.- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data sources such as Sentry issues and Supabase logs. While this represents a potential ingestion surface for indirect prompt injection, it is a standard and necessary component for the skill's primary monitoring purpose and carries low inherent risk in this context.
Audit Metadata