context-engineering
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides educational content and templates for optimizing AI agent context without executing any code or performing unexpected network operations.
- [DATA_EXPOSURE_EXFILTRATION]: The skill explicitly warns against committing sensitive files like '.env' and secrets, promoting secure development practices and secret management.
- [INDIRECT_PROMPT_INJECTION]: The skill contains a dedicated section on 'Trust levels for loaded files', correctly identifying external docs and user-submitted content as untrusted. It provides mitigation guidance by advising agents to treat instruction-like content in those files as data rather than directives and to surface such content to the user for verification.
- [COMMAND_EXECUTION]: Example commands provided in the 'CLAUDE.md' template (e.g., build, test, lint) are standard development workflow tasks and are presented for documentation purposes only, not for silent execution.
Audit Metadata