smapi-best-practices

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of technical documentation and code templates for C# developers. Analysis of the provided files (SKILL.md and the references/ directory) confirms that it does not perform network operations, access sensitive system files, or include obfuscated code.
  • [PROMPT_INJECTION]: The skill is designed to review and refactor user-provided mod source code and project metadata, creating an inherent attack surface for indirect prompt injection.
  • Ingestion points: The skill workflow involves processing project files such as manifest.json, .csproj, and ModEntry.cs (as detailed in the Core Workflow section of SKILL.md).
  • Boundary markers: No specific boundary markers or instructions to disregard embedded instructions within user data are present in the provided markdown files.
  • Capability inventory: The skill does not instruct the agent to utilize shell execution tools, network tools, or sensitive file system access; its operations are confined to logic analysis and C# code refactoring.
  • Sanitization: The skill's instructions do not implement sanitization or validation of strings derived from user-provided code files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 10:42 AM
Security Audit — agent-trust-hub — smapi-best-practices