pflow-task-implement

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for manual implementation of tasks within a local development environment. It uses localized references and scripts to manage the workflow without external network dependencies or unsafe command execution.- [COMMAND_EXECUTION]: The skill executes a specific helper script to interact with the mdtodo CLI. This script is restricted via allowed-tools and uses secure parameter handling and JSON escaping when reading task metadata.- [SAFE]: The inclusion of a .env loader in the bash script is a standard method for managing local project configuration and does not represent an unsafe credential handling practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 01:52 PM
Security Audit — agent-trust-hub — pflow-task-implement