scope-triage
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a process-oriented workflow designed to help AI agents decide whether a request requires a full design cycle or can go straight to implementation. It contains no executable scripts, shell commands, or network operations.- [CREDENTIALS_SAFE]: The skill contains explicit instructions in Step 0 and Route A to never reproduce secrets, tokens, or passwords. It mandates the use of placeholder names like <API_TOKEN> to ensure sensitive data is not written to logs or files.- [DATA_INJECTION_DEFENSE]: The Security Model section explicitly identifies repository files, command outputs, and logs as untrusted evidence. It instructs the agent to extract facts from these sources but never to execute or follow instructions embedded within them, providing a defense against indirect prompt injection.
Audit Metadata