development-workflow
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill incorporates a mandatory security review phase (review:security-review) that audits all modified files for vulnerabilities like SQL injection and XSS before finalizing development.
- [SAFE]: Critical operations such as creating git branches or choosing code execution strategies (Batch, Subagent, or Agent Team) are gated by explicit user prompts and confirmation.
- [SAFE]: File access is restricted to legitimate project artifacts such as ARCHITECTURE.md, CLAUDE.md, and planning documents within the project directory.
- [SAFE]: External capabilities are handled through specialized framework skills or subagents, with no evidence of unauthorized remote code execution or data exfiltration.
- [SAFE]: Potential indirect prompt injection risks associated with reading project files are mitigated by the workflow's multi-step review and verification processes.
Audit Metadata