shortform-packaging

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a local bash script, scripts/verify.sh, to lint the structure of its generated package files. Analysis of the script confirms it is a read-only, network-free utility that uses standard text-processing tools (awk, grep, sed) to validate labels and formatting without executing file content.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill reads brand guidelines and logs from the local 02-DOCS/ directory to inform its creative output. It does not access sensitive system paths, credentials, or environment variables, and no network exfiltration patterns were identified.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface through reading local performance logs. This surface is low-risk as the skill's capabilities are limited to generating marketing copy, and it implements structural verification to ensure output consistency. The ingestion points include the 02-DOCS/ tree, with boundary markers established by YAML frontmatter and specific markdown sections.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — shortform-packaging