mvp-first

Pass

Audited by Gen Agent Trust Hub on Apr 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local bash commands such as git rev-parse and git branch to collect environment metadata (branch name, commit hash). It also uses filesystem commands like mkdir and ln for managing project artifacts in the memory/artifacts/ directory. These are routine operations for developer-focused tools and are limited to the local environment.
  • [SAFE]: The skill's operations are confined to the local project environment. It does not perform external network requests, access sensitive credentials (like SSH keys or AWS tokens), or download/execute untrusted remote code. The instructions are focused on product planning and methodology rather than system manipulation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 19, 2026, 10:00 AM
Security Audit — agent-trust-hub — mvp-first