cc-skill-project-guidelines-example

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and code templates for project architecture and development workflows. All identified patterns are standard for the described tech stack.
  • [COMMAND_EXECUTION]: Includes standard development commands for testing (pytest, npm test) and deployment (gcloud run deploy). These commands are contextual and do not pose a risk in the provided documentation format.
  • [CREDENTIALS_UNSAFE]: Mentions environment variables and API keys in the deployment section, but uses explicit placeholders (e.g., sk-ant-..., eyJ...) instead of real secrets, following standard documentation practices.
  • [PROMPT_INJECTION]: Contains a code example for LLM integration. While this code represents a surface for indirect prompt injection if processing untrusted data, it is presented as a functional template and does not contain malicious instructions itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:18 PM
Security Audit — agent-trust-hub — cc-skill-project-guidelines-example