skills/blockmatic/first/f/Gen Agent Trust Hub

f

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a structured framework for auditing and improving repository quality across multiple domains (Product, Security, Architecture, etc.). It operates entirely within the local repository context.\n- [COMMAND_EXECUTION]: The f-designer skill references using npx @google/design.md lint to validate design tokens. This is a standard linting tool from a well-known vendor (Google) and is used for local validation.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data by reading repository-local files (e.g., _first/FIRST.md and various instance files) to drive its analysis. However, it incorporates strong defensive instructions, such as the 'Analyst posture' which requires the agent to explicitly label findings as 'Fact', 'Inference', or 'Assumption', and specifically instructs the agent to stop and ask a human for secrets or trust-boundary edits. These markers and human-in-the-loop requirements mitigate the risk of accidental obedience to instructions embedded in repo data.\n- [CREDENTIALS_SAFE]: The skill contains explicit instructions in references/analyst.md and f-security/references/spec.md to identify secrets as sensitive and to avoid committing them or logging them. It mandates human approval for security-consequential changes. No hardcoded credentials or private keys were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:18 PM
Security Audit — agent-trust-hub — f