linuxmirrors-awesome

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and examples consistently emphasize that the agent should only provide information and route users to appropriate workflows. It explicitly prohibits direct system changes, modifications to /etc, or running commands like 'curl | bash' within the scope of this skill (SKILL.md).
  • [SAFE]: The documentation includes an HTML evaluation report that loads a CSS framework from a well-known CDN (tailwindcss.com). This is a standard practice for rendering documentation and is considered safe (evaluation-report.html).
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it is designed to fetch and verify information from external sources like GitHub and the LinuxMirrors official website. However, the risk is minimal due to the lack of executable capabilities and strong boundary instructions.
  • Ingestion points: External project URLs and source code repositories (references/official/sources.md).
  • Boundary markers: The skill includes a 'Quality Checklist' and 'Rules' that mandate verification and prohibit executing suggested commands (SKILL.md, references/operations/quality-checklist.md).
  • Capability inventory: The skill does not possess any shell execution, file writing, or network-sending tools.
  • Sanitization: None specified, but the agent is restricted to informational output only.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 08:14 AM
Security Audit — agent-trust-hub — linuxmirrors-awesome