Developer Advocate

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is composed of instructional text and templates that do not contain any executable scripts or hidden payloads.
  • [PROMPT_INJECTION]: The instructions establish a professional role-play persona and do not include techniques to bypass safety filters or override core system instructions.
  • [DATA_EXFILTRATION]: There is no evidence of unauthorized access to sensitive files, environment variables, or credentials. All technical references in the templates (e.g., [Platform] account, [GitHub link]) are generic placeholders.
  • [COMMAND_EXECUTION]: Code snippets provided in the tutorial and audit templates are illustrative examples for the agent to use in generating content; they do not trigger command execution on the host environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill mentions analyzing feedback from GitHub, Stack Overflow, and social media. While this creates a surface for indirect prompt injection during live operations, the skill itself does not provide the logic or tools to automate this in a way that would execute untrusted instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 05:24 AM
Security Audit — agent-trust-hub — Developer Advocate