@tank/idd-bdd-pack

Pass

Audited by Gen Agent Trust Hub on May 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
  • [SAFE]: The skill's content is purely instructional, focusing on software development methodologies and traceability between architectural intent and verification tests. No malicious prompts or behavior overrides were detected.
  • [EXTERNAL_DOWNLOADS]: The skill defines dependencies on other skills from the same author, specifically @tank/idd and @tank/bdd-e2e-testing. These references represent internal vendor resources within the skill's defined repository (github.com/tankpkg/skills) and follow standard modular design practices.
  • [DATA_EXFILTRATION]: While the skill manifest requests broad read-access to the project filesystem (**/*), it explicitly disables network outbound permissions and subprocess execution. This configuration allows the agent to analyze project structures for documentation purposes while preventing the transmission of data to external systems.
  • [NO_CODE]: The skill does not bundle any executable scripts, binaries, or automated tasks. All logic and workflows are delivered as natural language instructions and reference documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 31, 2026, 11:04 PM
Security Audit — agent-trust-hub — @tank/idd-bdd-pack