north-star-metric

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill includes a Python script (scripts/metric_tree_builder.py) that uses only standard libraries to process JSON specifications into text-based formats (Mermaid, Markdown, etc.). A review of the source code confirms it does not perform network operations, spawn subprocesses, or access sensitive file paths.
  • [SAFE]: No patterns of prompt injection, such as attempts to bypass safety filters or override system instructions, were found in the skill's markdown files.
  • [SAFE]: The skill does not contain any obfuscated content, hardcoded credentials, or persistence mechanisms. All URLs and references point to educational resources and industry-standard frameworks.
  • [SAFE]: The skill's metadata and instructions are consistent with its stated purpose of assisting project managers with metric definition and alignment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 09:18 AM
Security Audit — agent-trust-hub — north-star-metric