agents-md

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate workspace discovery by reading project configuration files (such as package.json, go.mod, and *.code-workspace) and tech stack indicators to generate documentation.
  • [SAFE]: No malicious patterns such as credential harvesting, remote code execution, or obfuscation were found in the skill's instructions or logic.
  • [SAFE]: The behavioral guidelines and operational defaults (like 'Caveman Communication') are intended for workflow management and do not attempt to bypass agent safety filters.
  • [SAFE]: The data ingestion process for project metadata includes normalization for project identifiers, which mitigates the risk of indirect injection from discovered workspace content.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 06:59 AM
Security Audit — agent-trust-hub — agents-md