product-roadmap

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill interacts with GitHub repositories using the authenticated gh CLI, adhering to standard security practices for external tool integration.
  • [SAFE]: The HTML template (references/roadmap-template.html) includes a robust escaping function (esc) to prevent Cross-Site Scripting (XSS) by sanitizing untrusted content retrieved from GitHub issues and pull requests.
  • [SAFE]: The workflow incorporates a 're-run contract' (Step 1) and explicit approvals for environment modifications, ensuring that the skill does not make unauthorized changes to the user's workspace.
  • [SAFE]: A detailed verification gate (references/self-checks.md) is mandatory for the agent to follow, which includes checking artifact integrity, grounding claims in real code primitives, and re-verifying the live state of all cited items.
  • [SAFE]: The skill uses selection caps and honest reporting for large data sets (Step 3), preventing accidental processing of excessive data or fabrication of missing information.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 12:49 PM
Security Audit — agent-trust-hub — product-roadmap