agent-protocol

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is protocol design and validation. The Python scripts included for capability mapping and validation use safe methods like json.load for data processing and ast.parse for source code analysis, presenting no inherent risk.
  • [COMMAND_EXECUTION]: Documentation in references/errors-testing-and-quality.md includes an example of integration testing using subprocess.Popen. This is a standard development practice for testing local service availability and is presented as educational context, not as an active vulnerability.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides scripts that ingest external JSON schemas. While these are external inputs, the scripts perform technical validation rather than processing natural language instructions that could influence agent behavior, effectively mitigating injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 08:34 PM
Security Audit — agent-trust-hub — agent-protocol