Developer Advocate
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is composed of instructional text and templates that do not contain any executable scripts or hidden payloads.
- [PROMPT_INJECTION]: The instructions establish a professional role-play persona and do not include techniques to bypass safety filters or override core system instructions.
- [DATA_EXFILTRATION]: There is no evidence of unauthorized access to sensitive files, environment variables, or credentials. All technical references in the templates (e.g., [Platform] account, [GitHub link]) are generic placeholders.
- [COMMAND_EXECUTION]: Code snippets provided in the tutorial and audit templates are illustrative examples for the agent to use in generating content; they do not trigger command execution on the host environment.
- [INDIRECT_PROMPT_INJECTION]: The skill mentions analyzing feedback from GitHub, Stack Overflow, and social media. While this creates a surface for indirect prompt injection during live operations, the skill itself does not provide the logic or tools to automate this in a way that would execute untrusted instructions.
Audit Metadata