decision-mapping

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to manage project state via a git-tracked markdown file. It does not perform unauthorized network operations, access sensitive system directories, or contain obfuscated code.
  • [PROMPT_INJECTION]: The skill includes instructions to load the decision map as context. While this data is untrusted (as it can be edited by users or other sessions), this is the intended design for stateful planning. There are no attempts to override agent safety protocols or system prompts.
  • [COMMAND_EXECUTION]: The skill workflow involves invoking other agent-specific tools (such as /prototype or /grilling). These operations occur within the agent's controlled execution environment and do not involve arbitrary shell commands or privilege escalation.
  • [DATA_EXFILTRATION]: There is no evidence of data being transmitted to external domains. File operations are restricted to the project's own documentation and assets.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 12:22 PM
Security Audit — agent-trust-hub — decision-mapping