best-practices-delivery-proof
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill contains test configuration in
fixtures/agentic_eval.jsonand a sanity check scriptsanity.shthat utilize shell commands, includinguv runto execute internal Python tools. These are intended for verification and automated evaluation of the skill's adherence to its own rules. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it ingests untrusted data. 1. Ingestion points:
scripts/assess.pyreads incident files andscripts/enforce_read_gate.pyreads session transcripts from stdin. 2. Boundary markers: None identified. 3. Capability inventory: Scripts are limited to programmatic diagnostics and exit codes; no network operations or arbitrary file writes are triggered by ingested data. 4. Sanitization: Data is parsed as JSON, but no specific prompt-injection filtering is applied to the content. - [EXTERNAL_DOWNLOADS]: The skill relies on external Python packages
typerandpyyamldefined inpyproject.toml. These are fetched from official package registries using theuvtool during environment setup.
Audit Metadata