generate-custom-instructions-from-codebase

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of structured instructions and prompt templates. It does not contain executable scripts, binaries, or commands that could compromise the host environment.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill directs the agent to analyze project source code and configuration files to identify changes. However, it does not target sensitive system locations (like .ssh or .aws directories), nor does it include any network-related commands (like curl or wget) to exfiltrate data.
  • [PROMPT_INJECTION]: The instructions are focused on code analysis and migration documentation. There are no attempts to bypass safety filters, extract system prompts, or override the core behavior of the AI agent.
  • [COMMAND_EXECUTION]: No shell commands or system-level operations are defined within the skill. The generation of a local markdown file (.github/copilot-migration-instructions.md) is a standard development practice for configuring GitHub Copilot.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 07:48 AM
Security Audit — agent-trust-hub — generate-custom-instructions-from-codebase