routines-discover

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs static project analysis by reading local files. It does not initiate network connections, execute arbitrary commands, or exfiltrate data. It follows standard agent analysis patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local project files which could contain instructions intended to influence the agent's analysis.
  • Ingestion points: README.md, CLAUDE.md, package.json, Cargo.toml, pyproject.toml, .github/workflows/, and .claude/settings.json.
  • Boundary markers: Absent.
  • Capability inventory: The skill is limited to reading files and outputting text recommendations; it lacks the capability to write files, execute subprocesses, or perform network operations.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 07:37 AM
Security Audit — agent-trust-hub — routines-discover