ask
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed for technical analysis and architectural guidance within a local project environment. No malicious patterns were identified during the audit.
- [PROMPT_INJECTION]: The skill uses repetitive, high-emphasis language such as 'MANDATORY IMPORTANT MUST ATTENTION' to enforce the use of specific tools (e.g., TaskCreate) and documentation standards. These instructions are focused on operational quality and do not attempt to bypass core safety filters or redefine the agent's underlying safety protocols.
- [DATA_EXFILTRATION]: The skill references local project files (e.g., ./.claude/workflows/ and ./docs/) to provide context for architectural answers. There are no network operations, hardcoded credentials, or patterns suggesting the unauthorized removal of data from the system.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided technical questions through the $ARGUMENTS variable. While this is an ingestion point for untrusted data, the skill's activities are limited to providing architectural advice and reading local documentation, which minimizes the risk of exploitable side effects.
Audit Metadata