project-development-review-v2
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is to perform structured reviews of development artifacts. It instructs the agent to read relative file paths (e.g.,
../project-development-v2-common/) which is standard behavior for development-oriented agents. No sensitive system paths or hardcoded credentials were identified. - [SAFE]: There are no external network requests, remote code executions, or package installations. The skill consists entirely of Markdown instructions and YAML configuration.
- [SAFE]: The instructions do not contain prompt injection attempts or obfuscation techniques. The logic focuses on identifying development risks like 'mocked results' or 'unverifiable evidence' in user projects.
- [SAFE]: Indirect Prompt Injection Surface: While the skill ingests untrusted data (development documents), its purpose is to analyze and find faults in that data rather than executing it. It lacks dangerous capabilities like shell execution or network writing that could be triggered by malicious content in the audited documents.
Audit Metadata