xy-development

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents best practices for development, including TypeScript conventions, Git workflows, and testing principles without any malicious instructions.
  • [SAFE]: Includes explicit security guidance in 'workflow.md' regarding credential safety, advising against committing secrets like .env files or .npmrc tokens and ensuring they are added to .gitignore.
  • [SAFE]: Promotes the use of official repository toolchains (pnpm, yarn, npm) and standard package management procedures.
  • [SAFE]: References to external documentation (Conventional Commits, Gitflow) and internal packages (@xyo-network/*) are legitimate and consistent with the vendor context.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 06:18 AM
Security Audit — agent-trust-hub — xy-development