agents-md

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily instructional documentation focused on the best practices for managing AGENTS.md and CLAUDE.md files. It defines strict security boundaries between 'Trusted' and 'Untrusted' audit modes, explicitly warning against executing any code from untrusted repositories.
  • [SAFE]: The documentation includes detailed 'Containment rules for untrusted audits' in references/spec.md, which provides technical guidance on preventing path traversal, symlink escapes, and unauthorized execution when dealing with potentially malicious repositories.
  • [SAFE]: The skill emphasizes 'least privilege' for AI agents, specifically advising that commands like deployments or database resets should never be verified by execution, but rather through static source code analysis or dry-run flags.
  • [SAFE]: No obfuscated URLs, hardcoded credentials, or suspicious third-party dependencies were detected. The references to agentskills.io and code.claude.com are for official documentation purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 04:47 PM
Security Audit — agent-trust-hub — agents-md