check-setup-against-standards

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the uv run command to execute a local audit script located at ../set-up-env/scripts/audit.py. This operation is used solely for the stated purpose of auditing repository configurations and is restricted by the skill's platform configuration.
  • [PROMPT_INJECTION]: The skill is subject to a surface for indirect prompt injection as it processes files from potentially untrusted repositories. Maliciously crafted content within the audited files could attempt to influence the agent's final report or summary.
  • Ingestion points: Reads and parses files within the target repository using the audit.py script (e.g., pyproject.toml, .gitignore).
  • Boundary markers: No explicit delimiters or instructions are used to separate audited content from the agent's instructions.
  • Capability inventory: The skill has access to Read and Bash (restricted to uv run) tools.
  • Sanitization: The audit script produces structured JSON output, which provides a layer of data isolation before the results are presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 04:18 AM
Security Audit — agent-trust-hub — check-setup-against-standards