skills/goldk3y/skills/build-with-docs/Gen Agent Trust Hub

build-with-docs

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute build, test, and linting commands to verify code changes (SKILL.md Phase 5). These operations are scoped to the local repository and are performed as part of the intended development process.
  • [EXTERNAL_DOWNLOADS]: The workflow involves researching official documentation and maintainer repositories (references/research-guide.md). The skill provides a 'source quality ladder' that prioritizes trusted organizations and well-known services, which reduces the risk associated with untrusted external content.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it processes data from external sources and the local codebase.
  • Ingestion points: Research results from external documentation sites and content from local repository files, including manifests and source code (SKILL.md Phase 1 & 2).
  • Boundary markers: None explicitly defined in the prompt text, although the workflow follows a structured checklist.
  • Capability inventory: The agent is authorized to read/write files and execute local commands for building and testing code (SKILL.md Phase 4 & 5).
  • Sanitization: The references/review-checklist.md includes a specific 'Security and production concerns' section that mandates validating all external input and checking for hardcoded secrets, serving as a functional mitigation strategy.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 10:34 PM
Security Audit — agent-trust-hub — build-with-docs