render
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions and associated scripts were analyzed across all 11 threat categories, and no security issues were detected.
- [DATA_EXPOSURE]: The skill explicitly promotes security best practices for handling sensitive information. It instructs the agent to use
sync: falseorgenerateValue: truefor secrets inrender.yamlto prevent them from being committed to version control. - [DYNAMIC_EXECUTION]: The provided
scripts/verify.shuses a Python heredoc to perform YAML linting. This implementation is safe as it usesyaml.safe_load()to prevent arbitrary code execution during parsing and limits its operations to local file reading and stdout reporting. - [INDIRECT_PROMPT_INJECTION]: While the skill includes a tool to process user-provided
render.yamlfiles, it does not possess any dangerous capabilities (network access, file writing, or shell execution of file content) that could be exploited via malicious configuration data.
Audit Metadata