open-project

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or security vulnerabilities were detected.
  • [DATA_EXPOSURE]: The skill interacts with local markdown files using a configuration-based path system. It does not access sensitive system directories (such as SSH or AWS credentials) or perform any network operations to exfiltrate data.
  • [PROMPT_INJECTION]: The skill includes instructions that restrict agent autonomy, such as the 'secretary' stance and 'hybrid ban', which prevent the agent from performing unauthorized product work or bypassing project limits.
  • [COMMAND_EXECUTION]: There are no shell commands, subprocess calls, or dynamic code execution patterns identified in the skill scripts or instructions.
  • [EXTERNAL_DOWNLOADS]: The skill does not reference or attempt to download any external packages, scripts, or remote content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 07:01 AM
Security Audit — agent-trust-hub — open-project