devpilot-auto-feature
Pass
Audited by Gen Agent Trust Hub on May 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security vulnerabilities, malicious code, or unauthorized data exfiltration patterns were identified. The skill follows established software engineering practices.\n- [COMMAND_EXECUTION]: The skill executes project-specific tools (e.g.,
openspec,devpilot-pr-creator) and development sub-skills (e.g.,superpowers:test-driven-development). These operations are transparently documented as part of the core feature implementation workflow and are used to manage local code and pull requests.\n- [PROMPT_INJECTION]: The skill processes project specifications and instructions from external files (OpenSpec proposals). This data ingestion is handled within the context of implementation tasks and does not involve instructions aimed at overriding agent behavior or bypassing safety filters.
Audit Metadata