dev-context-engineering
Pass
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
- [SAFE]: The skill provides templates and guidelines for implementing security best practices in repository management, including PII detection and signed commit enforcement.
- Assets like
compliance-fca-emi.mdanddata-handling-gdpr-pci.mdexplicitly prohibit the storage of sensitive data (PII, card data, credentials) in AI context files. - The
fca-compliance-gate.ymlworkflow template implements automated security checks using industry-standard tools like Gitleaks and Semgrep. - [COMMAND_EXECUTION]: Documentation includes instructions and shell templates for running local scripts and git commands to manage repository context.
- Templates for
sync-rules.shandvalidate-repos.share provided for administrative oversight and rule propagation across multiple repositories. - The
repo-conversion-playbook.mdprovides terminal commands for codebase orientation and architecture extraction. - [EXTERNAL_DOWNLOADS]: The
data/sources.jsonfile contains a curated list of 83 URLs referencing documentation, research papers, and regulatory guidelines. - Sources include official documentation from Anthropic, OpenAI, Google, and Microsoft, as well as regulatory guidance from the FCA, NIST, and FINRA.
- [NO_CODE]: The skill does not distribute standalone executable scripts or binary files, relying instead on markdown-based instructions and a GitHub Actions workflow configuration.
Audit Metadata