open-project
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or security vulnerabilities were detected.
- [DATA_EXPOSURE]: The skill interacts with local markdown files using a configuration-based path system. It does not access sensitive system directories (such as SSH or AWS credentials) or perform any network operations to exfiltrate data.
- [PROMPT_INJECTION]: The skill includes instructions that restrict agent autonomy, such as the 'secretary' stance and 'hybrid ban', which prevent the agent from performing unauthorized product work or bypassing project limits.
- [COMMAND_EXECUTION]: There are no shell commands, subprocess calls, or dynamic code execution patterns identified in the skill scripts or instructions.
- [EXTERNAL_DOWNLOADS]: The skill does not reference or attempt to download any external packages, scripts, or remote content.
Audit Metadata