best-practices-port
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes an evaluation fixture in
fixtures/agentic_eval.jsonthat defines a command to execute a local Python script (validate_skill.py) from a relative parent directory (../../best-practices-skills/scripts/). This execution pattern is restricted to local static validation of the skill's metadata and contract within a controlled development environment. - [SAFE]: The instructions in
SKILL.mdare purely technical and focus on engineering standards, parity mapping, and preservation of destination architecture. No patterns of prompt injection, obfuscation, or unauthorized data access were detected. - [SAFE]: External resource references (e.g.,
Memory-first,SciLLM,DAG) appear to be part of the internal architectural components of the 'Tau' and 'Pi' harnesses described in the skill, rather than external untrusted dependencies.
Audit Metadata