goodharts-law

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill definition and associated examples consist entirely of natural language instructions and educational content. No malicious patterns, obfuscation, or suspicious command executions were identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting user-provided data about organizational metrics and goals. While this represents an ingestion point for untrusted data, the skill does not request or utilize tools for network access, file system modifications, or shell execution, thereby presenting no meaningful attack surface for exploitation.
  • [COMMAND_EXECUTION]: No shell commands, scripts, or binary executions are contained within the skill or its references.
  • [EXTERNAL_DOWNLOADS]: All external links point to the vendor's official domain (deciqai.com) or repository (github.com/deciqai), which is consistent with the skill's authorship.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 08:14 AM
Security Audit — agent-trust-hub — goodharts-law