auditing-a-repository

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No attempts to override safety filters or bypass agent instructions were detected. The skill uses standard instructional language to guide repository audits.
  • [DATA_EXFILTRATION]: The skill does not contain logic for exfiltrating sensitive data. While it instructs the agent to search for secrets within a repository (as part of a security audit), it does not provide mechanisms to transmit this data externally.
  • [REMOTE_CODE_EXECUTION]: There is no evidence of remote code execution or unauthorized package installation. The skill references well-known, reputable security tools (e.g., Checkov, Trivy, kube-linter) for the purpose of auditing, all of which are hosted by trusted organizations or well-known services.
  • [OBFUSCATION]: The content is clear and readable. No Base64, zero-width characters, homoglyphs, or other obfuscation techniques were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface by ingesting repository data for analysis. However, it mitigates this risk through strict instructions to cite only evidence present in scans and provides clear boundary markers for report synthesis.
  • [SAFE]: The skill follows best practices for repository-shaped audits, utilizing a modular lens-based architecture. All external links and dependencies are to reputable industry-standard tools and research sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 11:24 PM
Security Audit — agent-trust-hub — auditing-a-repository