shipping-artifacts

Pass

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves exclusively as a structural guideline for documentation. It does not contain executable code, script generation, network operations, or attempts to access sensitive system files.
  • [COMMAND_EXECUTION]: The documentation references external slash commands such as /document-app, /derive-tests, and /ship-check as the intended mechanisms for generating these artifacts. These references are purely descriptive of the intended workflow and do not constitute shell command execution or subprocess spawning within the skill itself.
  • [CREDENTIALS_UNSAFE]: The skill mandates the creation of a variables.md artifact to track configuration and secrets. Rather than exposing credentials, it enforces security best practices by requiring explicit confirmation that no secrets are bundled client-side and identifying rotation plans for risk management.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 4, 2026, 05:23 AM
Security Audit — agent-trust-hub — shipping-artifacts