setup-task-to-pr

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses standard system utilities such as rg, find, and git to perform read-only inspection of repository structure and configuration files (e.g., package.json, pyproject.toml).
  • [SAFE]: The skill's operations are limited to generating or updating project-specific documentation (SKILL.md) in designated local directories (.agents/skills/, etc.), which is consistent with its stated purpose.
  • [SAFE]: References to external components such as agent-browser and supa-skills are identified as vendor-owned resources originating from the same author (supatest-ai).
  • [SAFE]: No patterns of data exfiltration, credential harvesting, privilege escalation, or code obfuscation were found within the instructions or the discovery commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 07:55 PM
Security Audit — agent-trust-hub — setup-task-to-pr