skills/ericrisco/rsc-harness/render/Gen Agent Trust Hub

render

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and associated scripts were analyzed across all 11 threat categories, and no security issues were detected.
  • [DATA_EXPOSURE]: The skill explicitly promotes security best practices for handling sensitive information. It instructs the agent to use sync: false or generateValue: true for secrets in render.yaml to prevent them from being committed to version control.
  • [DYNAMIC_EXECUTION]: The provided scripts/verify.sh uses a Python heredoc to perform YAML linting. This implementation is safe as it uses yaml.safe_load() to prevent arbitrary code execution during parsing and limits its operations to local file reading and stdout reporting.
  • [INDIRECT_PROMPT_INJECTION]: While the skill includes a tool to process user-provided render.yaml files, it does not possess any dangerous capabilities (network access, file writing, or shell execution of file content) that could be exploited via malicious configuration data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — render