Document ReviewSAFE
A framework-agnostic, git-native standard for defining AI agents
Overview
A framework-agnostic, git-native standard for defining AI agents
799d6d0ad18cOBSERVED · 2026-10-07What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: document-review description: "Reviews financial documents (prospectuses, ADVs, marketing materials) for FINRA 2210 compliance, required disclosures, and balanced presentation. Use when reviewing financial statements, audit documents, regulatory filings, or when the user mentions compliance checks, financial audits, or document verification." license: proprietary allowed-tools: search-regulations generate-report metadata: author: gitagent-examples version: "1.0.0" category: compliance risk_tier: high --- # Document Review ## Instructions When reviewing a financial document: 1. **Classify the document** — Determine document type (prospectus, ADV, customer agreement, marketing material, etc.) 2. **Identify applicable rules** — Map to FINRA 2210 (communications), SEC disclosure requirements, etc. 3. **Check required elements** — Verify all required disclosures, disclaimers, and content are present 4. **Assess accuracy** — Flag potentially misleading, exaggerated, or promissory statements 5. **Check balance** — Per FINRA 2210, ensure risks and benefits are presented in a balanced manner 6. **Review formatting** — Verify required prominence of disclosures ## Key Checks - [ ] All required disclosures present - [ ] No misleading or exaggerated claims - [ ] Balanced presentation of risks and benefits - [ ] Proper disclaimers included - [ ] Correct classification (correspondence/retail/institutional) - [ ] Principal pre-approval status verified (if retail communication) ## Output Format For each finding, produce: ``` ### [SEVERITY] — [Rule Reference] - **Issue**: [What was found] - **Location**: [Section/page reference] - **Recommended action**: [Specific fix] ``` ### Example Finding ``` ### WARNING — FINRA 2210(d)(1)(A) - **Issue**: Performance claim "consistently outperforms the market" lacks supporting data and time period - **Location**: Page 2, paragraph 3 - **Recommended action**: Add specific time period, benchmark comparison, and standardized performance data per SEC Rule 482 ```
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
799d6d0ad18cfull audit observations/trust-audit/skill/open-gitagent__document-review.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 799d6d0ad18c | SAFE | B | 89 | first audit |
Questions
What does the Document Review skill do?
A framework-agnostic, git-native standard for defining AI agents
Is Document Review safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Document Review access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (799d6d0ad18c), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.