research-publishing
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill provides security-focused guidance by instructing the agent to scan for hardcoded credentials, API tokens, sensitive file paths, and private infrastructure references to ensure they are removed before code is published.
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external content (the user's repository files and code). While this represents a surface for indirect prompt injection if the files being audited contain malicious instructions, the skill's activities are limited to generating reports and recommendations, which minimizes risk.
- Ingestion points: The agent audits the user's repository files, dependencies, and code comments.
- Boundary markers: None specified in the instructions.
- Capability inventory: Reading file content, listing directory structures, and performing pattern matching (regex/grep) on local files.
- Sanitization: No specific sanitization methods are mentioned for the audited content.
- [COMMAND_EXECUTION]: The skill mentions using tools like 'grep' to perform sensitive content scans on the repository. This is a standard diagnostic activity performed on the local environment and does not involve executing arbitrary or remote commands.
Audit Metadata