elephant-build
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive instructions for secure software development, including mandatory input validation using Zod, multi-tenant data isolation, and the use of safe error-handling patterns through the Signpost system.
- [COMMAND_EXECUTION]: The development workflow involves executing local CLI tools like pnpm, gw, and uv for component auditing and visual regression testing. These are standard development practices restricted to the local environment and the project's own tooling.
- [DATA_EXFILTRATION]: Secret management instructions correctly advise the use of local environment files (.env.local) and environment templates (.env.example). No patterns suggesting unauthorized data transmission or exfiltration were identified.
Audit Metadata