nlp-engineering

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command to identify installed companion skills for environment awareness.
  • Evidence: The "Companion check" section in SKILL.md uses the ls command to scan directories like ~/.claude/skills/ and ~/.agent/skills/ to see which recommended skills are present.
  • [DATA_EXPOSURE]: The skill accesses filesystem paths within the user's home directory to verify the presence of related tools.
  • Evidence: The skill checks for the existence of specific directories related to the AI agent's environment to provide a better user experience through tailored skill recommendations.
  • [CREDENTIALS_UNSAFE]: Educational code snippets for external APIs use secure placeholders.
  • Evidence: Examples for OpenAI and Cohere in SKILL.md and references/embedding-models.md utilize placeholders such as "YOUR_API_KEY" or empty constructors, preventing the accidental exposure of real credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit — agent-trust-hub — nlp-engineering