best-practices-prompt

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The run.sh script executes local system utilities including grep, sed, bash, and python3 to perform static analysis and generate review reports. These operations are scoped to local files provided by the user.
  • [EXTERNAL_DOWNLOADS]: The review tool interacts with local network endpoints http://127.0.0.1:8601 (Memory Daemon) and http://localhost:4001 (Local LLM API). These are used for storing review history and performing local prompt optimization, respectively. No external remote downloads or executions were detected.
  • [DATA_EXFILTRATION]: The skill manages prompt review history and notes using browser localStorage and a local ArangoDB instance. Sensitive data handling is restricted to the local environment.
  • [SAFE]: The HTML review template (template.html) implements proper security practices by using .textContent for rendering untrusted data and applying HTML escaping before generating annotated views, mitigating potential script injection from analyzed prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — best-practices-prompt