skills/thaitype/chief/chief-plan/Gen Agent Trust Hub

chief-plan

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill does not perform arbitrary shell command execution. Its operations are limited to reading from and writing to project-specific files within the .chief/ directory and common project files like AGENTS.md.
  • [DATA_EXFILTRATION]: No network activity, such as HTTP requests or external data transfers, was detected. The skill's scope is strictly confined to the local filesystem.
  • [PROMPT_INJECTION]: The skill uses authoritative language ('Follow this process strictly', 'NEVER SKIP THIS PHASE') to maintain its internal workflow, but these do not constitute malicious injection attempts to bypass safety filters or extract system prompts.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving the download of external scripts or the execution of remote code. The skill is purely instructional and file-based.
  • [SAFE]: The skill incorporates strong safety practices by requiring explicit user approval ('STOP' gates) before transitioning between phases and before writing new content to the disk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 12:35 AM
Security Audit — agent-trust-hub — chief-plan