production-grade
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is composed of Markdown documentation and YAML frontmatter. It does not contain executable scripts or binary files.
- [INDIRECT_PROMPT_INJECTION]: The skill explicitly addresses the risk of indirect prompt injection. Meta-rule M2 (Context first, continuously learning) instructs the agent to treat all data harvested from external sources (such as documentation, MCP outputs, or third-party repositories) as untrusted data that informs decisions rather than instructions that direct actions. This provides a strong defensive posture against malicious instructions embedded in external content.
- [COMMAND_EXECUTION]: While the skill instructions refer to the agent reading the codebase (e.g., using
cat,ls, orgit log), these are standard development operations intended to gather context. The skill includes specific warnings (R7, R16) against generating code that performs unsafe execution or SQL injection. - [DATA_EXFILTRATION]: No patterns for unauthorized data access or network exfiltration were identified. The skill promotes secure engineering practices, such as constant-time secret comparisons and avoiding PII in logs.
- [EXTERNAL_DOWNLOADS]: The skill references several well-known and trusted technology services (e.g., Cloudflare, Vercel, AWS) and open-source repositories (e.g.,
anthropics/skills,donnemartin/system-design-primer) as authoritative sources for engineering patterns. These are documented neutrally as fitting the skill's purpose of providing canonical references.
Audit Metadata