prompt-governance
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of Markdown instructions and documentation. It does not include any scripts (Python, Node.js, Shell), configuration for external tools, or executable artifacts.
- [DATA_EXFILTRATION]: There are no network-capable commands or instructions to move data to external servers. All data management described (prompt registries, versioning) is relative to the user's local directory structure.
- [REMOTE_CODE_EXECUTION]: No remote scripts or packages are downloaded or executed. The skill focuses on methodology rather than automation via code.
- [PROMPT_INJECTION]: The instructions do not contain patterns designed to bypass AI safety filters or override core agent behavior. The language is professional and focused on DevOps best practices for prompt engineering.
- [INDIRECT_PROMPT_INJECTION]: While the skill involves the agent reading user-provided content (like
project-context.mdor existing prompt files), the skill itself does not provide executable tools or shell capabilities that could be exploited via malicious content in those files.
Audit Metadata