prd-v07-epic-scoping

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes the Bash tool exclusively for standard Git operations, such as creating branches (git checkout -b) and managing commits. These operations are restricted to project management workflows and do not involve unauthorized system modifications.
  • [SAFE]: The skill reads and inventories project specifications (API contracts, data models, and architecture decisions). While this creates a surface for indirect prompt injection from technical files, the skill manages this risk through the use of 'Context Capsules' and explicit context budget guidelines that limit the volume and scope of processed data.
  • [SAFE]: No external network requests, suspicious downloads, or credential harvesting patterns were detected. References to third-party services like Supabase or Clerk are documented only as examples of architectural dependencies and do not involve functional code execution or data exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 09:42 PM
Security Audit — agent-trust-hub — prd-v07-epic-scoping