ai-engineer

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No attempts to override agent behavior, bypass safety filters, or extract system prompts were detected.
  • [DATA_EXFILTRATION]: No network operations, sensitive file paths, or hardcoded credentials were found. The instructions explicitly advise avoiding sending sensitive data to external models without approval.
  • [REMOTE_CODE_EXECUTION]: The skill consists entirely of markdown instructions and does not perform any remote code downloads or package installations.
  • [COMMAND_EXECUTION]: No shell commands, subprocess spawning, or dynamic context injection patterns (e.g., backtick commands) are present.
  • [OBFUSCATION]: The content is clear-text markdown with no signs of Base64, hex encoding, zero-width characters, or homoglyph attacks.
  • [INDIRECT_PROMPT_INJECTION]: While the skill describes capabilities for building RAG systems and agents that process external data, the skill itself does not implement vulnerable data ingestion or prompt interpolation logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 01:28 AM
Security Audit — agent-trust-hub — ai-engineer