skills/bcgen/skills/skill-auditing/Gen Agent Trust Hub

skill-auditing

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a diagnostic utility that reads local skill files and performs web searches to verify the accuracy of commands, APIs, and version numbers.
  • [SAFE]: No indicators of malicious activity such as credential harvesting, data exfiltration, or unauthorized command execution were found.
  • [PROMPT_INJECTION]: An indirect prompt injection surface is present in Step 3, where the skill ingests external content from web searches and documentation fetches.
  • Ingestion points: Web search results and official documentation pages (SKILL.md).
  • Boundary markers: None explicitly mentioned in instructions to separate external data from system prompts.
  • Capability inventory: The skill has no inherent execution or write capabilities; it reports findings and suggests edits for manual review or delegation to a separate skill.
  • Sanitization: Not explicitly defined.
  • [SAFE]: The skill adheres to the 'diagnose, don't mutate' principle, ensuring that all proposed changes are presented for user approval or handled by an external writing skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 08:03 AM
Security Audit — agent-trust-hub — skill-auditing