skills/davidlee/doctrine/preflight/Gen Agent Trust Hub

preflight

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains no executable code, scripts, or binary files. It consists entirely of natural language instructions for task planning and cognitive organization.
  • [SAFE]: No network operations, data exfiltration patterns, or attempts to access sensitive credentials or environment variables were detected.
  • [SAFE]: The skill does not request or use elevated privileges, persistence mechanisms, or obfuscated commands.
  • [PROMPT_INJECTION]: The skill processes untrusted user input through the $ARGUMENTS placeholder and reads external artifacts, creating a potential surface for indirect prompt injection. Ingestion points: $ARGUMENTS variable and external project artifacts/files mentioned in search order. Boundary markers: None explicitly defined in the prompt instructions. Capability inventory: None; the skill is instructional and does not define or use high-risk tools like shell execution, network requests, or file writes. Sanitization: None. Given the absence of dangerous capabilities within the skill itself, this processing surface is considered safe for its intended purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 12:02 AM
Security Audit — agent-trust-hub — preflight