release-spec

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates with a restricted set of tools, specifically Read, Write, Glob, and Grep, which are used exclusively for documentation processing and generation within the project workspace.
  • [SAFE]: All remote links and third-party tools suggested in the generated guides (e.g., Fastlane, Apple Developer Portal, Firebase, Figma) are established, well-known services within the software development industry.
  • [SAFE]: The provided templates for GitHub Actions and privacy manifests demonstrate security awareness by using secrets for credential management and promoting accurate data privacy disclosures.
  • [SAFE]: No evidence of prompt injection, data exfiltration, obfuscation, or persistence mechanisms was found in the skill's instructions or metadata.
  • [SAFE]: The skill's surface for indirect prompt injection was evaluated. While it ingests content from multiple local markdown files, the lack of high-risk capabilities like shell execution or network requests ensures the process remains safe.
  • Ingestion points: product-plan-*.md, docs/ARCHITECTURE.md, docs/IMPLEMENTATION_GUIDE.md, docs/TEST_SPEC.md
  • Boundary markers: Absent
  • Capability inventory: Read, Write, Glob, Grep, AskUserQuestion
  • Sanitization: Absent
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 01:19 PM
Security Audit — agent-trust-hub — release-spec