best-practices-prompt
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The
run.shscript executes local system utilities includinggrep,sed,bash, andpython3to perform static analysis and generate review reports. These operations are scoped to local files provided by the user. - [EXTERNAL_DOWNLOADS]: The review tool interacts with local network endpoints
http://127.0.0.1:8601(Memory Daemon) andhttp://localhost:4001(Local LLM API). These are used for storing review history and performing local prompt optimization, respectively. No external remote downloads or executions were detected. - [DATA_EXFILTRATION]: The skill manages prompt review history and notes using browser
localStorageand a local ArangoDB instance. Sensitive data handling is restricted to the local environment. - [SAFE]: The HTML review template (
template.html) implements proper security practices by using.textContentfor rendering untrusted data and applying HTML escaping before generating annotated views, mitigating potential script injection from analyzed prompts.
Audit Metadata