devdocs-pipeline
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
Tasktool to coordinate and invoke other internal skills (e.g.,/devdocs-requirements,/devdocs-system-design). This is a legitimate use of the tool for workflow orchestration and does not involve arbitrary or malicious command execution. - [DATA_EXPOSURE]: The skill interacts with files located within the
docs/devdocs/directory to track project progress and manage context. It does not access sensitive system paths, environment variables, or hardcoded credentials. - [PROMPT_INJECTION]: The skill contains clear operational constraints and routing instructions. No patterns of safety filter bypass, role-play injections, or instructions to ignore system guidelines were identified.
- [EXTERNAL_DOWNLOADS]: The skill does not perform any network operations or external downloads. All operations are restricted to the local filesystem and internal tool calls.
Audit Metadata