building-agents
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements proactive security measures for tool execution, including command allowlisting and path traversal prevention using a resolution utility that validates paths against a root directory.
- [SAFE]: It includes a dedicated guardrail implementation that uses regex-based heuristics to detect and block prompt injection attempts and redact Personally Identifiable Information (PII) before it is processed or logged.
- [SAFE]: The architecture promotes the use of structured output with strict schema validation (via Pydantic and Zod), which prevents common issues related to malformed model outputs or 'parse-and-pray' anti-patterns.
- [SAFE]: It provides guidance on supply chain security, specifically advising on the use of pinned versions for dependencies (e.g., litellm) to avoid versions associated with security advisories.
- [SAFE]: The skill incorporates bounded agent loops with explicit step caps, timeouts, and cost budgets, effectively preventing denial-of-service scenarios and runaway API costs.
Audit Metadata