git-native-context-contract

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines an instructional process for creating and reviewing Markdown-based project context. It implements a 'proposal-first' workflow which ensures all changes are inspected by a human before being applied to the repository.
  • [SAFE]: The lifecycle management for 'accepted' documents requires explicit human identification, timestamps, and references to external authorization (e.g., a PR or meeting record), preventing the agent from autonomously modifying the project's authoritative records.
  • [SAFE]: The 'Authority and storage' section contains strong security guidance, specifically forbidding the copying of secrets, private customer data, or protected evidence into documentation files.
  • [SAFE]: No remote execution, network calls, or external package dependencies were found. The skill operates within the existing file structure of the user's repository.
  • [SAFE]: No obfuscation techniques, malicious metadata poisoning, or prompt injection vectors were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 03:53 PM
Security Audit — agent-trust-hub — git-native-context-contract