using-galyarder-framework

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill does not contain any malicious code, obfuscation, or unauthorized data access patterns. It is a framework for organizing agent behavior and engineering practices.
  • [PROMPT_INJECTION]: The skill uses highly assertive language (e.g., "MANDATORY", "NOT NEGOTIABLE", "IRON LAW") to enforce its framework protocols and override default agent behavior. However, it explicitly includes a priority list where "User's explicit instructions" are ranked as the highest priority, and it includes security-positive directives such as redacting PII and secrets.
  • [INDIRECT_PROMPT_INJECTION]: The skill proactively addresses the risks of processing untrusted data. It explicitly labels web content and external data (e.g., via BrowserOS) as "hostile" and instructs the agent to treat these inputs as untrusted, recommending the redaction of sensitive information before further processing.
  • [EXTERNAL_DOWNLOADS]: The skill recommends several third-party MCP servers (RTK, Linear, BrowserOS, Context7) and provides links to their official documentation or GitHub repositories. These are presented as optional infrastructure recommendations for the framework and do not involve automated or silent installation of untrusted software.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 07:36 AM
Security Audit — agent-trust-hub — using-galyarder-framework