entity-model-auditor
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security threats detected. The skill's functionality is limited to processing text-based inputs (PRDs and code snippets) and generating a structured markdown report.
- [DATA_INJECTION_SURFACE]: The skill processes untrusted external data (user-provided PRDs and codebase files). While it lacks the capabilities to perform dangerous actions like network requests or file modifications, it follows the pattern of ingesting third-party content into the agent's context.
- Ingestion points: Processes user-provided PRD text and referenced codebase files (SKILL.md, Step 1).
- Boundary markers: None present to distinguish instructions from user-provided data.
- Capability inventory: No dangerous tools (shell execution, network access, file system writes) are present in the skill's instructions or metadata.
- Sanitization: No explicit sanitization of input data is described.
Audit Metadata