ai-agents
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The strings identified by static analysis in
references/agent-security-governance.mdare documented examples of attack vectors within a threat modeling section. They do not constitute an attempt to subvert the agent's behavior. - [REMOTE_CODE_EXECUTION]: No remote code execution or suspicious download patterns were found. The skill provides architectural templates and local code examples for educational and design purposes.
- [CREDENTIALS_UNSAFE]: No hardcoded credentials or sensitive data exposure points were identified. The documentation correctly suggests using environment variables and secret management for production systems.
- [DATA_EXFILTRATION]: No exfiltration patterns were detected. The skill is entirely focused on providing architectural knowledge and design templates.
- [COMMAND_EXECUTION]: The skill mentions shell execution tools in its security reference material as examples of high-risk capabilities that require human-in-the-loop oversight, but it does not execute arbitrary commands.
Audit Metadata