deploy-checklist
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data by reading source code files using the Read and Grep tools. Without boundary markers, instructions embedded in these files could attempt to influence audit results. Ingestion points: Read, Glob, Grep tools (SKILL.md). Boundary markers: Absent. Capability inventory: Read, Glob, Grep. Sanitization: None.
- [DATA_EXPOSURE]: The skill searches for sensitive strings like API keys and reads environment files. This is consistent with its role as a security auditor and does not involve exfiltration.
Audit Metadata