dev-workflow-planning

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily composed of architectural and procedural guidance. All external references point to reputable technology vendors (Anthropic, OpenAI, AWS, GitHub) or established industry frameworks (DORA, Scrum, EARS).
  • [REMOTE_CODE_EXECUTION]: Instructions regarding package installation (npm, pip) and command execution (npx, k6) are focused on the validation and deployment of the user's application code as part of a structured delivery process.
  • [INDIRECT_PROMPT_INJECTION]: The skill uses an interactive 'interview phase' to gather requirements. Risk is mitigated by the workflow's requirement to produce bounded plan contracts and explicit success criteria.
  • [DYNAMIC_EXECUTION]: Local script references for feedback loops (append_learning.py) and cost calculations (cost_uncertainty.py) are appropriate for the skill's utility and do not process untrusted external inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — dev-workflow-planning