project-guides

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructional content for humans (SMEs) on how to write effective and safe documentation for AI agents. No malicious behavior or code is present within the skill body.
  • [EXTERNAL_DOWNLOADS]: The skill explicitly prohibits the use of polyfill.io, which is a known security best practice due to past compromises of that service. It also provides guidance on conditional loading of polyfills to minimize performance and security risks.
  • [COMMAND_EXECUTION]: While the skill mentions the use of a CLI tool (gd dev, gd pr) for development workflows, these are described as internal tools used to generate evaluation reports and manage pull requests. The skill notes that these tools run evaluations inside safe temporary sandboxes (/tmp/).
  • [DYNAMIC_EXECUTION]: The skill describes a build-time macro system (e.g., {{ BASELINE_STATUS }}) used to inject browser compatibility data and reusable feature descriptions into the final documentation. These are standard static site generation patterns and do not involve runtime execution of untrusted code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:46 AM
Security Audit — agent-trust-hub — project-guides