devdocs-feature
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or security risks were identified in the skill instructions or templates.
- [COMMAND_EXECUTION]: The skill requests access to the
Bashtool. While powerful, its use is consistent with the skill's stated purpose of scanning project documents and managing a developer workspace. - [DATA_EXFILTRATION]: No network-related tools or commands (e.g., curl, wget) are used, and no attempts to access sensitive system files or credentials were found.
- [PROMPT_INJECTION]: The skill interprets user feature descriptions to determine the development mode (Lite vs. Full). It follows a structured orchestration logic that mandates user confirmation at key steps, which serves as a manual guardrail against unintended actions.
Audit Metadata