definition-of-done

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's logic is restricted to reading project requirements and writing enhanced milestones to a local YAML file. It serves a legitimate documentation purpose without interacting with sensitive system files.
  • [REMOTE_CODE_EXECUTION]: Analysis of the instructions and examples reveals no attempts to download or execute external code, scripts, or packages.
  • [COMMAND_EXECUTION]: The skill does not invoke shell commands, subprocesses, or system utilities beyond standard file I/O for project artifacts.
  • [DATA_EXFILTRATION]: No network access or outbound communication patterns (e.g., HTTP requests, data posting) are present, ensuring data remains within the local project environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:59 PM
Security Audit — agent-trust-hub — definition-of-done