orchestrate-features

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill manages and launches sub-agents using a defined Agent() pattern with isolation="worktree". This is a standard orchestration pattern for developer productivity tools and includes isolation as a built-in security measure.
  • [DATA_EXPOSURE]: The skill reads from local paths such as .claude/features/ and .claude/rules/. These are project-specific configuration paths and do not represent unauthorized access to sensitive user data or system credentials.
  • [PROMPT_INJECTION]: The skill defines a structured orchestration workflow. While it reads external feature specifications that could theoretically contain conflicting instructions, the orchestrator instructions emphasize following specific rules and updating statuses, which aligns with expected behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 03:46 AM