create-service-object

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No prompt injection, DAN, or behavioral override patterns were detected. The instructions follow standard technical guidance.
  • [SAFE]: No hardcoded credentials, sensitive file path access, or unauthorized network operations were found. The code examples use generic placeholders.
  • [SAFE]: No obfuscation techniques, such as Base64 encoding of executable content, zero-width characters, or homoglyph attacks, were identified.
  • [SAFE]: The skill does not perform external package installations or execute remote code (e.g., via curl | bash).
  • [SAFE]: No privilege escalation commands (like sudo) or persistence mechanisms (like cron jobs or shell profile modifications) were found.
  • [SAFE]: No dynamic execution patterns, such as eval() or unsafe deserialization, were present in the Ruby templates.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Ruby params hashes defined in service skeletons across SKILL.md and assets/template.rb.
  • Boundary markers: Not applicable as the skill provides code templates rather than processing live data streams.
  • Capability inventory: Includes database transaction wrapping and application logging in assets/service_skeleton.md.
  • Sanitization: The skill explicitly requires SQL sanitization for all dynamic queries in the constraints section of SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:22 PM
Security Audit — agent-trust-hub — create-service-object