best-practices-skills

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a security framework that defines and enforces non-negotiable access policies, such as restricting direct database access to a single authorized skill, thereby preventing unauthorized data exposure.
  • [SAFE]: The validation logic in scripts/validate_skill.py uses secure YAML parsing (yaml.safe_load) to analyze skill metadata, preventing code execution risks associated with untrusted data deserialization.
  • [SAFE]: Structural checks in sanity.sh and the validation scripts ensure that heavy artifacts are stored on designated high-capacity drives via symlinks, maintaining the integrity and performance of the root filesystem.
  • [SAFE]: No indicators of malicious behavior, such as prompt injection, obfuscation, hardcoded secrets, or unauthorized network operations, were found during the analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — best-practices-skills