repoint-project

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses clear, instructional language to define a specific workflow. It does not contain any attempts to bypass AI safety guardrails, override system prompts, or solicit restricted information.
  • [DATA_EXFILTRATION]: There are no network-related commands (like curl or wget) or functions that send data to external domains. The skill only reads and writes local documentation files (e.g., docs/product/pivot-ledger.md) within the project's repository.
  • [COMMAND_EXECUTION]: The skill instructions include basic file system navigation (cd) and file writing to manage project documentation. It does not execute arbitrary shell commands, manage system services, or attempt to escalate privileges. The frontmatter specifically includes 'disable-model-invocation: true', which limits the agent's autonomy.
  • [EXTERNAL_DOWNLOADS]: The skill does not reference or download any external scripts, binaries, or packages. It relies entirely on standard markdown documentation files within the local environment.
  • [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or sensitive file paths (like .ssh or .aws) are accessed or referenced. The skill's scope is strictly limited to product and architecture documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 05:48 AM
Security Audit — agent-trust-hub — repoint-project