context-engineering

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides educational content and templates for optimizing AI agent context without executing any code or performing unexpected network operations.
  • [DATA_EXPOSURE_EXFILTRATION]: The skill explicitly warns against committing sensitive files like '.env' and secrets, promoting secure development practices and secret management.
  • [INDIRECT_PROMPT_INJECTION]: The skill contains a dedicated section on 'Trust levels for loaded files', correctly identifying external docs and user-submitted content as untrusted. It provides mitigation guidance by advising agents to treat instruction-like content in those files as data rather than directives and to surface such content to the user for verification.
  • [COMMAND_EXECUTION]: Example commands provided in the 'CLAUDE.md' template (e.g., build, test, lint) are standard development workflow tasks and are presented for documentation purposes only, not for silent execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — context-engineering