skills/spm1001/bon/review/Gen Agent Trust Hub

review

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local commands such as bon and uv to manage backlog items. These operations are scoped to the user's local repositories and are consistent with the skill's stated purpose.
  • [EXTERNAL_DOWNLOADS]: All scripts and resources used by the skill are local. No network connections or downloads of external code were identified during the analysis.
  • [PROMPT_INJECTION]: The skill uses subagents to verify the status of items described in the backlog. While these agents process external data (the item briefs), they are explicitly restricted to read-only operations and the final execution of changes is protected by a mandatory user-approval step.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 08:43 AM
Security Audit — agent-trust-hub — review