acceptance-criteria-review
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of Markdown and YAML configuration files. There are no scripts (Python, JavaScript, shell) or binaries included, which eliminates categories related to code execution, persistence, or privilege escalation.
- [SAFE]: All instructions focus on document review processes, logical analysis of requirements, and senior QA best practices. The skill specifically instructs the agent to perform no unauthorized production writes or destructive actions.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes user-supplied requirements and user stories (ingestion surface), it includes explicit instructions to 'separate confirmed facts, working assumptions, and open questions' and 'never invent system behavior,' which serves as a logical boundary against instruction overrides embedded in processed data.
- [CREDENTIALS_SAFE]: The skill explicitly advises using 'masked data' and 'isolation' for sensitive work and does not contain any hardcoded secrets or access patterns for credential files.
Audit Metadata