sparkfinderoven-security-compliance-skills
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill package is composed entirely of instructions, command definitions, and example outputs. There are no functional scripts or executable components provided within the file.
- [EXTERNAL_DOWNLOADS]: The instructions include a reference to a GitHub repository for manual installation (github.com/sparkfinderoven/r01-hesreallyhim-awesome-claude-code-security). As this is an installation reference and not a runtime operation, it does not pose a direct execution risk.
- [PROMPT_INJECTION]: The skill is intended to process external data such as source code and architecture diagrams, which presents a surface for indirect prompt injection. However, the instructions do not contain malicious overrides and rely on standard AI safety guardrails.
- Ingestion points: Local source code directories, architecture diagram files (.drawio), and JSON data inventories.
- Boundary markers: No specific delimiters or boundary warnings are included in the instruction set.
- Capability inventory: The skill is strictly instructional and does not possess capabilities to execute subprocesses, write files, or perform network operations autonomously.
- Sanitization: No explicit sanitization or validation logic is defined within the prompt instructions.
Audit Metadata