shortform-format-selector

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The repository includes a shell script tests/validate_repo.sh which the user is instructed to run for local environment validation. The script performs file structure checks, executes a Python script via stdin for JSON schema validation, and runs a regex-based secret scan to ensure the repository remains clean of credentials.
  • [DATA_EXFILTRATION]: The skill incorporates a local credential scanner within its test suite to help users identify and remove sensitive data before sharing. The README.md and SKILL.md files provide clear warnings against storing credentials, client data, or private assets within the repository.
  • [EXTERNAL_DOWNLOADS]: The skill's installation process utilizes the standard npx skills tool to fetch resources from the author's own repository (Jaycheng1103/content-kitchen-format-selector). All referenced external resources are part of the vendor's own infrastructure.
  • [PROMPT_INJECTION]: The skill includes explicit instructions and evaluation cases to prevent the AI from exceeding its defined scope. It forbids the generation of full scripts, hooks, or commercial outcome guarantees, and enforces a mandatory rights-check gateway for any third-party content.
  • [SAFE]: The skill demonstrates security-conscious design by including built-in validation tests, clear boundary markers for user input processing, and localized processing rules that minimize the risk of accidental safety violations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 06:56 PM
Security Audit — agent-trust-hub — shortform-format-selector