project-structure

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill explicitly instructs the agent to follow security best practices, such as sanitizing user-controlled data, using secure password hashing, and avoiding the exposure of secrets in code or logs. It provides templates for secure backend organization and promotes the use of validation schemas to prevent invalid data ingestion.\n- [PROMPT_INJECTION]: The skill requires the agent to inspect existing project files, which serves as a surface for indirect prompt injection from codebase content. This is a low-risk, inherent requirement of the skill's purpose and is mitigated by instructions to prioritize security in generated outputs.\n
  • Ingestion points: Project source code, directory structures, and configuration files analyzed during the 'Before Writing Code' phase.\n
  • Boundary markers: The skill does not define specific delimiters for separating project content from agent instructions.\n
  • Capability inventory: Code generation, refactoring recommendations, and project structure modification.\n
  • Sanitization: The skill mandates that the agent include validation and sanitization logic in any code it generates for the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 07:36 PM
Security Audit — agent-trust-hub — project-structure