scroll-engineering
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is purely instructional and contains no executable scripts or binaries. It guides the agent through a manual or automated audit process.
- [DATA_EXPOSURE]: No hardcoded credentials, API keys, or sensitive file paths were detected. The skill uses a default local directory for reporting audit results.
- [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote scripts. All auditing is performed on the user's provided codebase or live URL using standard agent tools.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data (code or UI behavior) for auditing. While this creates a theoretical attack surface for indirect prompt injection, the risk is minimal as the skill's capabilities are restricted to generating a text-based audit report and it explicitly forbids the agent from implementing code changes based on the audit.
Audit Metadata