first-time-user-ucv-cli
Pass
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes standard system utilities such as
grepandlsto locate documentation files. It also runs a project-specific script (npm run ucv-cli) to test the functionality of the command-line interface. These actions are strictly local and align with the skill's stated purpose of auditing tool usability. - [DATA_EXFILTRATION]: There are no network operations or attempts to access sensitive system files (e.g., credentials, SSH keys, or environment variables). All file interactions are restricted to the project's documentation and audit directories.
- [EXTERNAL_DOWNLOADS]: The skill does not perform any remote downloads, package installations, or script execution from external sources.
- [PROMPT_INJECTION]: The use of a 'confused newcomer' persona is a simulation technique for UX testing. It does not contain instructions to bypass safety guidelines, extract system prompts, or override the agent's core operating principles.
- [SAFE]: All identified behaviors are consistent with a benign developer tool focused on documentation testing and user experience auditing.
Audit Metadata