best-practices-chat
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: A test fixture in
fixtures/agentic_eval.jsonincludes a command to run a Python validation script (../../best-practices-skills/scripts/validate_skill.py). This is a local script execution intended for engineering standard compliance checks in a development environment. - [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for ingesting and displaying external compliance data which represents a theoretical attack surface.
- Ingestion points: Data rendered in
InlineEvidenceCase,InlineArtifact, andInlineFigureas specified inSKILL.md. - Boundary markers: No specific delimiters or warnings for embedded instructions are provided in the UX guidelines.
- Capability inventory: The skill files contain no subprocess calls, file system writes, or network operations.
- Sanitization: No data sanitization or filtering logic is described in the guidelines.
Audit Metadata