shipping-and-launch
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is primarily instructional, offering a structured framework for staged rollouts, feature flagging, and rollback strategies without executing dangerous commands.
- [COMMAND_EXECUTION]: Mentions standard development tools such as
npm auditandnpx prisma migratewithin its documentation and templates. These are presented as manual verification steps for developers and do not constitute automated or hidden execution. - [DATA_EXFILTRATION]: Includes code snippets for error reporting (e.g.,
reportError) that use standard telemetry data like user IDs and URLs. This is typical for observability in production environments and is not configured to exfiltrate sensitive data to unauthorized external endpoints. - [PROMPT_INJECTION]: No evidence of instructions designed to bypass safety filters or override agent constraints was found. The instructions are aligned with the skill's stated purpose of preparing production launches.
Audit Metadata