github-repository-standards

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill promotes secure repository management practices, such as advising the use of environment variable templates (.env.example) rather than hardcoding sensitive credentials. It organizes project files into standard directories like .config/ and .github/, which enhances project maintainability without introducing security vulnerabilities.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it audits repository structures and reads file contents to generate documentation and relocation plans.\n
  • Ingestion points: The agent scans the root directory and reads file contents across the repository to identify configuration files and documentable assets.\n
  • Boundary markers: Boundary markers for untrusted repository content are not explicitly defined in the instructions.\n
  • Capability inventory: The skill's capabilities are limited to providing file relocation commands (mv) and suggesting updates to local configuration manifests such as package.json.\n
  • Sanitization: The skill does not implement specific sanitization for ingested repository data, relying on the agent's context processing to generate markdown and commands.\n- [COMMAND_EXECUTION]: The skill includes documentation and recipes that utilize standard developer tools and CLI commands, including npm, npx, stylelint, and docker. These commands are used for legitimate project configuration and verification purposes and do not execute unsanitized strings from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — github-repository-standards