setup-task-to-pr
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses standard system utilities such as
rg,find, andgitto perform read-only inspection of repository structure and configuration files (e.g., package.json, pyproject.toml). - [SAFE]: The skill's operations are limited to generating or updating project-specific documentation (SKILL.md) in designated local directories (.agents/skills/, etc.), which is consistent with its stated purpose.
- [SAFE]: References to external components such as agent-browser and supa-skills are identified as vendor-owned resources originating from the same author (supatest-ai).
- [SAFE]: No patterns of data exfiltration, credential harvesting, privilege escalation, or code obfuscation were found within the instructions or the discovery commands.
Audit Metadata