first-time-user-ucv-cli

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes standard system utilities such as grep and ls to locate documentation files. It also runs a project-specific script (npm run ucv-cli) to test the functionality of the command-line interface. These actions are strictly local and align with the skill's stated purpose of auditing tool usability.
  • [DATA_EXFILTRATION]: There are no network operations or attempts to access sensitive system files (e.g., credentials, SSH keys, or environment variables). All file interactions are restricted to the project's documentation and audit directories.
  • [EXTERNAL_DOWNLOADS]: The skill does not perform any remote downloads, package installations, or script execution from external sources.
  • [PROMPT_INJECTION]: The use of a 'confused newcomer' persona is a simulation technique for UX testing. It does not contain instructions to bypass safety guidelines, extract system prompts, or override the agent's core operating principles.
  • [SAFE]: All identified behaviors are consistent with a benign developer tool focused on documentation testing and user experience auditing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 10:46 AM
Security Audit — agent-trust-hub — first-time-user-ucv-cli