dev-flow
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as a high-level conductor that manages the order and invocation of other development-related skills without implementing dangerous logic itself.
- [SAFE]: A mandatory protocol step requires the agent to print an execution plan and wait for explicit user confirmation ("Confirm — user says go / edit / abort") before invoking any sub-skills. This prevents the autonomous execution of a chain of tools without oversight.
- [SAFE]: No patterns associated with data exfiltration, credential harvesting, or remote code execution were detected in the instructions or metadata.
- [SAFE]: The skill uses clear, logical gates for task routing (bug, feature, architecture, etc.) which helps ensure that higher-privilege or more complex operations are only performed when appropriate for the task tier.
- [SAFE]: References to external repositories and URLs point to the author's own infrastructure on GitHub (mqmalagris), which is consistent with the skill's authorship and contains no signs of typosquatting or malicious intent.
Audit Metadata