fp-brief
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements proactive security measures, including path normalization to prevent directory traversal (
..) and a redaction scan to identify and mask secrets or credentials before processing content. - [SAFE]: The skill uses
mcp__codex__codexfor verification. This tool is a vendor-owned resource for this skill author, and the implementation uses aread-onlysandbox with anapproval-policy: 'never'to ensure secure, non-modifying execution. - [SAFE]: Data exfiltration is mitigated by strict path validation enforcing repository boundaries (
git rev-parse --show-toplevel) and a local-first writing strategy.
Audit Metadata