kuroco-auth-design
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were detected. The skill is a documentation-only resource providing architectural guidance for Kuroco CMS.
- [PROMPT_INJECTION]: The instructions do not contain attempts to override AI safety filters or bypass system prompts. The content is strictly focused on Kuroco's configuration logic.
- [DATA_EXFILTRATION]: No network-related commands (curl, wget) or exfiltration patterns are present. The skill does not access sensitive local files or environment variables.
- [COMMAND_EXECUTION]: The skill contains no executable scripts or shell command strings. It does not utilize any tools that could execute code on the host system.
- [PRIVILEGE_ESCALATION]: The skill explicitly warns against architectural configurations that could lead to privilege escalation (e.g., granting non-admins both member and group update permissions). It functions as a security advisory rather than an attack vector.
Audit Metadata