dbx-skill-portfolio-auditor

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill inventories local skill directories and generates reports. No network exfiltration patterns were detected in the provided scripts or instructions. Scripts are restricted to the Python standard library and do not initiate network connections.
  • [REMOTE_CODE_EXECUTION]: All scripts use the Python standard library and run locally. There are no patterns of downloading and executing remote scripts or packages. The skill explicitly advises against destructive actions without user approval.
  • [PROMPT_INJECTION]: The skill includes explicit instructions to treat audited content as untrusted data and to ignore instructions embedded in third-party skill files, effectively mitigating potential indirect prompt injection attacks from the data it processes (Category 8 surface detection).
  • [COMMAND_EXECUTION]: The skill uses local Python scripts to facilitate the audit process. These scripts are deterministic and do not allow for arbitrary command injection or the execution of unsanitized user input.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 08:22 PM
Security Audit — agent-trust-hub — dbx-skill-portfolio-auditor