audit-security
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill establishes a read-only framework for auditing potentially untrusted data. Ingestion points: The workflow involves reading repository files, API definitions, and configurations (SKILL.md, workflow step 2). Boundary markers: The agent is required to state the audit scope and explicitly mark findings as 'Not verified' if evidence is missing (SKILL.md, Output Contract). Capability inventory: Access is restricted to reading delegated paths; the skill strictly prohibits editing files, creating commits, or running heavy scanners/network tests (SKILL.md, Hard Rules). Sanitization: Instructions emphasize grounding all findings in concrete evidence and distinguishing them from assumptions (SKILL.md, workflow step 9).
- [SAFE]: No obfuscation techniques, encoded payloads, or hidden URLs were detected. All external references are transparent and belong to the author's verified GitHub environment.
- [SAFE]: The skill does not contain prompt injection attempts. It focuses on reinforcing safety through clear 'Hard Rules' and 'Do Not Use For' sections that prevent the agent from performing unauthorized or harmful operations.
Audit Metadata