skills/rca32/skills/documenting-work/Gen Agent Trust Hub

documenting-work

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a bundled Python script, resolve_document_path.py, to calculate standardized documentation paths. The script employs argparse for safe argument handling and includes a slugify function that uses NFKC normalization and character filtering to ensure safe and portable filenames.\n- [COMMAND_EXECUTION]: The included test suite, scripts/test_resolve_document_path.py, uses subprocess.run() with argument lists to verify script behavior. This implementation avoids shell injection risks and is restricted to executing the local bundled script.\n- [SAFE]: The skill follows a well-defined lifecycle and authority matrix for documents, requiring verification of repository contracts and existing conventions before performing file operations. This structure minimizes the risk of accidental data corruption or unauthorized persistence.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 03:26 AM
Security Audit — agent-trust-hub — documenting-work