entity-model-auditor

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security threats detected. The skill's functionality is limited to processing text-based inputs (PRDs and code snippets) and generating a structured markdown report.
  • [DATA_INJECTION_SURFACE]: The skill processes untrusted external data (user-provided PRDs and codebase files). While it lacks the capabilities to perform dangerous actions like network requests or file modifications, it follows the pattern of ingesting third-party content into the agent's context.
  • Ingestion points: Processes user-provided PRD text and referenced codebase files (SKILL.md, Step 1).
  • Boundary markers: None present to distinguish instructions from user-provided data.
  • Capability inventory: No dangerous tools (shell execution, network access, file system writes) are present in the skill's instructions or metadata.
  • Sanitization: No explicit sanitization of input data is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 02:50 AM
Security Audit — agent-trust-hub — entity-model-auditor