strategic-execution-3d9

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: No hardcoded credentials, API keys, or sensitive file paths (e.g., .ssh, .aws) were found within the skill instructions or scripts.- [REMOTE_CODE_EXECUTION]: The skill does not include instructions to download and execute remote scripts or install unverified packages.- [INDIRECT_PROMPT_INJECTION]: The 'Coach mode' includes a step where the user describes a real-world case of execution failure. This provides a data ingestion surface; however, the skill lacks the necessary capabilities (such as file-writing tools or network exfiltration commands) to make this surface exploitable for malicious purposes.- [EXTERNAL_DOWNLOADS]: External URLs identified in the frontmatter and documentation point to the vendor's own domain (deciqai.com), their GitHub organization (github.com/deciqai), or reputable academic and archival sites (hbs.edu, archive.org, penguinrandomhouse.com), which are recognized as safe sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 08:15 AM
Security Audit — agent-trust-hub — strategic-execution-3d9