harden-security
Pass
Audited by Gen Agent Trust Hub on Jun 29, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data such as project source code and documentation for analysis, creating an attack surface for indirect prompt injection. This is effectively mitigated by the 'The Assayer'—a specialized skeptic agent tasked with adversarial review of all deliverables. Ingestion points: Project manifests, documentation files, and source code. Boundary markers: Project structure and role-scoped execution context. Capability inventory: Orchestrates sub-agents and performs local file access. Sanitization: Mandatory redaction of credentials from agent contexts.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill is designed to read and analyze local project files for security auditing purposes. This access is consistent with its intended function and no patterns of network exfiltration were found.
- [COMMAND_EXECUTION]: Coordinates complex tasks by spawning and managing specialized sub-agents via the Agent tool.
Audit Metadata