shipping-artifacts
Pass
Audited by Gen Agent Trust Hub on Jul 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves exclusively as a structural guideline for documentation. It does not contain executable code, script generation, network operations, or attempts to access sensitive system files.
- [COMMAND_EXECUTION]: The documentation references external slash commands such as
/document-app,/derive-tests, and/ship-checkas the intended mechanisms for generating these artifacts. These references are purely descriptive of the intended workflow and do not constitute shell command execution or subprocess spawning within the skill itself. - [CREDENTIALS_UNSAFE]: The skill mandates the creation of a
variables.mdartifact to track configuration and secrets. Rather than exposing credentials, it enforces security best practices by requiring explicit confirmation that no secrets are bundled client-side and identifying rotation plans for risk management.
Audit Metadata