devdocs-feature

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or security risks were identified in the skill instructions or templates.
  • [COMMAND_EXECUTION]: The skill requests access to the Bash tool. While powerful, its use is consistent with the skill's stated purpose of scanning project documents and managing a developer workspace.
  • [DATA_EXFILTRATION]: No network-related tools or commands (e.g., curl, wget) are used, and no attempts to access sensitive system files or credentials were found.
  • [PROMPT_INJECTION]: The skill interprets user feature descriptions to determine the development mode (Lite vs. Full). It follows a structured orchestration logic that mandates user confirmation at key steps, which serves as a manual guardrail against unintended actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 06:57 AM