dx-audit

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill facilitates developer onboarding audits and promotes secure handling of environment variables through the use of templates like .env.example to avoid secret exposure.
  • [EXTERNAL_DOWNLOADS]: References the author's GitHub repository for additional documentation, representing a legitimate vendor resource.
  • [COMMAND_EXECUTION]: Instructions include executing local project scripts to verify the onboarding workflow, which is consistent with the skill's stated purpose.
  • [PROMPT_INJECTION]: The skill ingests untrusted codebase data (README, guides) which serves as a potential indirect prompt injection surface. However, the skill contains no direct injection patterns, and its capabilities are scoped to project auditing and verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 10:36 PM
Security Audit — agent-trust-hub — dx-audit