build-support-agent
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is strictly instructional and serves as a build copilot. It does not contain any executable code, scripts, or network operations that run on the agent host system.
- [SAFE]: It promotes security best practices for the user's project, including timing-safe HMAC signature verification for webhooks and the use of dedicated secrets management tools (e.g., Doppler, AWS Secrets Manager).
- [SAFE]: External references and tool recommendations are limited to well-known and reputable services such as Anthropic, OpenAI, Vercel, Supabase, and Pinecone.
- [SAFE]: The skill provides guidance on handling customer data safely, including redacting PII before indexing knowledge bases.
Audit Metadata