project-guidelines-example
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a documentation template and architectural guide for developers. It does not contain any executable instructions that override agent safety or perform malicious actions.
- [CREDENTIALS_UNSAFE]: The deployment and configuration sections include environment variable examples (e.g., ANTHROPIC_API_KEY, SUPABASE_KEY). These are correctly implemented using placeholders like 'sk-ant-...' or 'eyJ...' rather than exposing actual secrets. The skill also explicitly includes a checklist item to ensure no hardcoded secrets are present.
- [COMMAND_EXECUTION]: Shell commands for testing (pytest, npm test) and deployment (gcloud run deploy) are provided as reference documentation for the user's workflow. There are no patterns involving the execution of untrusted remote scripts or hidden commands.
- [EXTERNAL_DOWNLOADS]: The skill mentions external services and official libraries (Supabase, Anthropic SDK). All references are to well-known services and do not involve downloading code from suspicious or untrusted sources.
Audit Metadata