skills/tstelzer/skills/ts-qa/Gen Agent Trust Hub

ts-qa

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for automated documentation generation (changelogs and QA plans) based on repository changes. It includes explicit instructions to avoid executing any code, scripts, or network calls during its analysis process.
  • [COMMAND_EXECUTION]: Employs standard development utilities such as git, rg (ripgrep), and fd for read-only analysis of the codebase and its history.
  • [DATA_EXPOSURE]: Accesses project source files, diffs, and version control history to understand implemented changes for reporting. It does not access sensitive system paths or credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted repository content (code and diffs) which serves as an injection surface; however, the impact is minimized by strict instructions to perform read-only inspection and output purely descriptive documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 08:47 AM
Security Audit — agent-trust-hub — ts-qa