release-spec
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates with a restricted set of tools, specifically
Read,Write,Glob, andGrep, which are used exclusively for documentation processing and generation within the project workspace. - [SAFE]: All remote links and third-party tools suggested in the generated guides (e.g., Fastlane, Apple Developer Portal, Firebase, Figma) are established, well-known services within the software development industry.
- [SAFE]: The provided templates for GitHub Actions and privacy manifests demonstrate security awareness by using secrets for credential management and promoting accurate data privacy disclosures.
- [SAFE]: No evidence of prompt injection, data exfiltration, obfuscation, or persistence mechanisms was found in the skill's instructions or metadata.
- [SAFE]: The skill's surface for indirect prompt injection was evaluated. While it ingests content from multiple local markdown files, the lack of high-risk capabilities like shell execution or network requests ensures the process remains safe.
- Ingestion points:
product-plan-*.md,docs/ARCHITECTURE.md,docs/IMPLEMENTATION_GUIDE.md,docs/TEST_SPEC.md - Boundary markers: Absent
- Capability inventory: Read, Write, Glob, Grep, AskUserQuestion
- Sanitization: Absent
Audit Metadata