best-practices-report
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary purpose is to enforce rigorous technical reporting standards. It provides HTML/CSS and Markdown templates for structured readouts.
- [SAFE]: No external network operations, sensitive file access, or suspicious command executions were found.
- [COMMAND_EXECUTION]: A fixture file (
fixtures/agentic_eval.json) includes a command to run a Python validation script (python3 ../../best-practices-skills/scripts/validate_skill.py). This is a standard testing pattern for skill validation and does not pose a security risk in this context. - [INDIRECT_PROMPT_INJECTION]: While the skill processes data to generate reports, it includes strict instructions for 'fail-closed semantics' and boundary markers (e.g., 'Non-Claims' sections and source-of-truth inventories) to prevent the AI from making unverified claims based on potentially malicious input data.
Audit Metadata