skills/baethon/skills/prd-self-audit/Gen Agent Trust Hub

prd-self-audit

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions are strictly task-oriented and do not contain patterns typical of prompt injection, such as attempts to bypass safety filters or disregard system instructions.
  • [DATA_EXFILTRATION]: No network-enabled tools (e.g., curl, wget) are used. The skill is documented to be non-interactive and does not transmit data to external domains.
  • [COMMAND_EXECUTION]: The skill does not utilize shell commands, subprocesses, or system-level APIs. Its functionality is limited to reading document prose and outputting a text report.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote scripts or packages.
  • [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or private credential paths are present in the skill files.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from PRDs and referenced files. While this represents a data ingestion surface, the risk is mitigated because the skill lacks exploitable capabilities like file modification or network access. Boundary markers are implicitly defined by the structured three-pass process and report format.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 09:18 PM
Security Audit — agent-trust-hub — prd-self-audit