repo-quality-system-lifecycle

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill package contains governance documentation and evaluation cases without any executable code. No malicious patterns or safety bypass attempts were identified.\n- [EXTERNAL_DOWNLOADS]: The skill documentation includes an installation command using npx to fetch arenukvern/skill_steward. This resource belongs to the skill author and is a legitimate part of the skill deployment process.\n- [INDIRECT_PROMPT_INJECTION]: The skill audits repository data such as documentation, plans, and schemas, which represents a potential attack surface for indirect prompt injection.\n
  • Ingestion points: The skill analyzes repository files including plans, specs, docs, maps, ADRs, FAQs, and schemas as described in SKILL.md.\n
  • Boundary markers: No specific delimiters or safety instructions for handling untrusted data were identified.\n
  • Capability inventory: The skill refers to using the steward CLI and standard repository validation commands (e.g., pnpm run eval).\n
  • Sanitization: The skill instructions do not explicitly require sanitization or filtering of the external repository content it processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:32 PM
Security Audit — agent-trust-hub — repo-quality-system-lifecycle