neo-agent-protocol
Pass
Audited by Gen Agent Trust Hub on Jul 26, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized access attempts were detected in the skill instructions or reference documentation.
- [NO_CODE]: The skill consists entirely of Markdown instructions and guidelines. There are no executable scripts, configuration files, or automated commands that could pose a direct security risk.
- [PROMPT_INJECTION]: The instructions do not attempt to bypass AI safety filters or override system instructions. Instead, they reinforce security by establishing "Safety Redlines" that require human intervention for high-risk operations like secret modification or destructive file system changes.
- [DATA_EXFILTRATION]: There are no indicators of data exfiltration. The skill explicitly warns against the exposure or modification of credentials and tokens.
- [REMOTE_CODE_EXECUTION]: The skill does not perform remote downloads or execute untrusted code. Mentions of commands like
npm testorcargo testare provided as examples for the agent to use during local verification tasks as part of a standard development workflow. - [COMMAND_EXECUTION]: While the skill encourages the use of local sensors (tests, linters, build tools), these are intended for legitimate software verification within the user's controlled development environment.
Audit Metadata