skills/idaibin/aicraft/audit-security/Gen Agent Trust Hub

audit-security

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses natural instructional language to define operational boundaries and limits. There are no attempts to bypass safety filters, extract system prompts, or override agent constraints. It explicitly includes 'Hard Rules' that reinforce safe behavior.
  • [EXTERNAL_DOWNLOADS]: The documentation references the author's own GitHub repository ('github.com/idaibin/aicraft') for skill installation and updates via the platform's standard 'npx' utility. This is a legitimate vendor resource used for routine maintenance.
  • [DATA_EXFILTRATION]: No network operations or instructions for transmitting sensitive data externally were found. The skill emphasizes read-only access to delegated paths and warns against leaking sensitive information in logs or error reports.
  • [COMMAND_EXECUTION]: The skill does not contain arbitrary shell command execution or instructions for subprocess spawning. It explicitly prohibits running heavy scanners, exploit attempts, or destructive checks without authorization.
  • [REMOTE_CODE_EXECUTION]: No patterns for downloading and executing untrusted remote scripts were identified. Standard package management tools are referenced solely for the skill's own installation from a known author repository.
  • [SAFE]: The skill demonstrates a strong security posture by defining clear trust boundaries, distinguishing between authentication and authorization, and requiring verification for all findings. It is designed to operate within a strictly scoped, read-only environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 02:26 PM
Security Audit — agent-trust-hub — audit-security