xy-development
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill documents best practices for development, including TypeScript conventions, Git workflows, and testing principles without any malicious instructions.
- [SAFE]: Includes explicit security guidance in 'workflow.md' regarding credential safety, advising against committing secrets like .env files or .npmrc tokens and ensuring they are added to .gitignore.
- [SAFE]: Promotes the use of official repository toolchains (pnpm, yarn, npm) and standard package management procedures.
- [SAFE]: References to external documentation (Conventional Commits, Gitflow) and internal packages (@xyo-network/*) are legitimate and consistent with the vendor context.
Audit Metadata