best-practices-delivery-proof

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains test configuration in fixtures/agentic_eval.json and a sanity check script sanity.sh that utilize shell commands, including uv run to execute internal Python tools. These are intended for verification and automated evaluation of the skill's adherence to its own rules.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it ingests untrusted data. 1. Ingestion points: scripts/assess.py reads incident files and scripts/enforce_read_gate.py reads session transcripts from stdin. 2. Boundary markers: None identified. 3. Capability inventory: Scripts are limited to programmatic diagnostics and exit codes; no network operations or arbitrary file writes are triggered by ingested data. 4. Sanitization: Data is parsed as JSON, but no specific prompt-injection filtering is applied to the content.
  • [EXTERNAL_DOWNLOADS]: The skill relies on external Python packages typer and pyyaml defined in pyproject.toml. These are fetched from official package registries using the uv tool during environment setup.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — best-practices-delivery-proof