agile-coach
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's instructions, metadata, and scripts were thoroughly audited, and no malicious patterns or security vulnerabilities were identified.
- [COMMAND_EXECUTION]: The skill includes Python scripts for maturity assessment and health checks. These scripts utilize only standard libraries (argparse, json, math, sys) for data processing and calculations, with no use of dangerous functions such as eval(), exec(), or subprocess calls.
- [DATA_EXFILTRATION]: There is no evidence of network activity or data exfiltration. The skill operates exclusively on local files provided by the user and outputs results to the standard output.
- [PROMPT_INJECTION]: The markdown documentation follows benign instructional patterns and does not contain attempts to override agent behavior or bypass safety guardrails.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests JSON and YAML data for analysis. The risk of injection is negligible as the scripts perform strict numerical type casting and structured parsing without executing content from the data or feeding it back into high-privilege operations.
Audit Metadata