foundation-prioritized-action-plan
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows an 'assume-nothing' architecture, requiring explicit user input and grounding all claims in a 'source ledger' to prevent hallucinations or unauthorized data use.
- [SAFE]: Network access is explicitly marked as out-of-scope in the instructions, and there are no instances of
curl,wget, or remote script fetching. - [SAFE]: External references (GitHub, Apache license) point to the author's own official organization (
product-on-purpose) or trusted standards, which is consistent with the vendor resource rules. - [SAFE]: The skill includes a 'handoff' mechanism to an orchestrator (
utility-pm-workflow-orchestrator), but it is governed by explicit user confirmation and operates through a separate, specialized skill rather than arbitrary code execution. - [SAFE]: No obfuscation, prompt injection, or privilege escalation patterns were detected in the instructions or example files.
Audit Metadata