lucidchart-sdk-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill proactively addresses secret management by instructing the agent that editor bundles must not contain server secrets and that credentials should be placed behind approved server boundaries.
  • [COMMAND_EXECUTION]: While the skill involves running build and test commands, it restricts these actions to using project-specific tooling and emphasizes following the help documentation of installed packages. It also requires explicit approval for broadening scopes or modifying dependencies.
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation from the Lucid developer portal (developer.lucid.co). These references are documented neutrally as legitimate development resources.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface involving the ingestion of local source code and official documentation. It mitigates this by instructing the agent to treat local installed types as the authoritative source of truth and to validate external data via typed boundaries.
  • [PROMPT_INJECTION]: No patterns for overriding safety guidelines or bypassing agent constraints were detected. The instructions focus on technical implementation and safety compliance.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:10 AM
Security Audit — agent-trust-hub — lucidchart-sdk-patterns