agentmd-maker
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a strong 'evidence over authority' policy in its instructions, specifically designed to mitigate indirect prompt injection by treating data from external files as information rather than instructions to be followed.
- [SAFE]: Explicit security contracts are defined to gate access to sensitive information, including credentials, private secrets, and network operations, ensuring no data exfiltration occurs without user consent.
- [SAFE]: Command execution is restricted to verified scripts and paths found within the repository's own manifests and configuration files, preventing the use of invented or malicious commands.
- [SAFE]: The skill includes defensive rules against destructive actions, unauthorized deployments, and persistence mechanisms, maintaining a strict least-privilege operational model.
- [SAFE]: Validation procedures include adversarial test cases that verify the agent's ability to reject malicious instructions embedded in project fixtures or retrieved content.
Audit Metadata