work-with-common-project-structure

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill describes and encourages the use of specific commands, scbuildcodeunit and scbuildcodeunitsc, to execute build and linting scripts directly on the host machine or within a containerized environment.
  • [EXTERNAL_DOWNLOADS]: The skill references a remote markdown file located at https://projects.aniondev.de/PublicProjects/Common/ProjectTemplates/-/raw/main/Conventions/RepositoryStructure/CommonProjectStructure/CommonProjectStructure.md. This is a resource belonging to the author's infrastructure used to provide project conventions.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by instructing the agent to ingest and follow instructions from an external data source.
  • Ingestion points: The agent is directed to read content from a remote URL on projects.aniondev.de as defined in SKILL.md.
  • Boundary markers: None. There are no instructions to the agent to distinguish between the provided data and instructions within the fetched content.
  • Capability inventory: The skill identifies capabilities for executing local shell commands (scbuildcodeunit).
  • Sanitization: None. The skill does not specify any validation or filtering for the external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 06:32 AM
Security Audit — agent-trust-hub — work-with-common-project-structure