code-quality

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains no executable code, shell scripts, or binaries. It is composed of markdown-based documentation and code examples intended for advisory purposes.
  • [SAFE]: No hardcoded credentials, secrets, or sensitive file path access patterns (e.g., .ssh, .aws) were detected in any of the 29 files.
  • [SAFE]: External references to libraries and frameworks (such as Zod, TanStack Query, and React) are well-known technology standards and are used in an educational context.
  • [PROMPT_INJECTION]: The skill's primary function involves processing external plans and codebases. This creates a surface for indirect prompt injection (Category 8), however, the skill does not include any high-risk capabilities (like shell execution or network exfiltration) that would allow for an exploit of this surface.
  • [SAFE]: No obfuscation techniques, hidden URLs, or deceptive metadata were found. The instructions align with the stated purpose of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 11:46 AM
Security Audit — agent-trust-hub — code-quality