adding-a-project

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local shell commands including 'make build' and 'git push' to automate the deployment workflow. This is consistent with its stated purpose of updating a personal website and resume.
  • [DATA_EXFILTRATION]: The skill reads and writes to local directories within the user's home folder. There is no evidence of sensitive data being exfiltrated to unauthorized external domains or third-party services.
  • [INDIRECT_PROMPT_INJECTION]: The skill incorporates user-provided project details into source files. While this represents a potential injection surface where external data could influence the compilation process (e.g., LaTeX injection), the risk is minimal as the actions are performed on the user's own local environment and repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 01:52 AM