ai-engineer

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFE
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses shell commands (cat) within SKILL.md to load shared protocol files and a production configuration. These commands are benign, localized to the project environment, and do not involve user input or network exfiltration.
  • [DATA_EXPOSURE]: The instructions mandate the use of environment variables or secrets managers for API keys, explicitly prohibiting hardcoding credentials in code.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies surfaces where external data (user requirements, codebases) is ingested as context in SKILL.md. Evidence chain: 1. Ingestion points: SKILL.md (Input Classification table); 2. Boundary markers: Absent; 3. Capability inventory: No dangerous tools or execution scripts are defined in this skill; 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 07:55 AM
Security Audit — agent-trust-hub — ai-engineer