rfu-audit

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a project management and utility auditing tool. It uses a structured methodology to evaluate project feasibility and does not perform any network operations or execute untrusted code.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local README.md and package.json files during its 'Auto-Analyze' phase. However, this risk is mitigated by the following:
  • Ingestion points: Project documentation files in the user's workspace.
  • Boundary markers: The extraction logic uses structured JSON prompts and markdown templates to isolate project data.
  • Capability inventory: The skill only has permissions to read local files and write audit reports to a dedicated .planning/audits/ directory. It cannot execute the content of the files it reads.
  • Sanitization: The skill explicitly requires human verification ('approve/edit/reject') for every piece of extracted information before it is used in the audit scoring process.
  • [DATA_EXPOSURE]: The skill accesses standard project indicators (e.g., package.json, Cargo.toml) to normalize project names and context. It does not access sensitive credential files like .ssh or .aws configurations.
  • [PERSISTENCE]: While the skill writes files to the .planning/ directory, this is for audit history tracking and does not attempt to modify shell profiles or system startup services.
  • [EXTERNAL_DOWNLOADS]: The skill includes links to its own GitHub repository (github.com/aplaceforallmystuff/claude-rfu-audit) for framework reference, which is consistent with the skill's author metadata and does not initiate unauthorized downloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 01:52 PM
Security Audit — agent-trust-hub — rfu-audit