skills/jpcaparas/skills/idiomatic/Gen Agent Trust Hub

idiomatic

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted workspace content, including source code, lockfiles, and configuration manifests. This creates an inherent attack surface for instructions embedded in analyzed data. However, the skill provides specific instructions to mitigate this, such as using fenced continuation prompts for handoffs and prioritizing synthetic fixtures over live data.
  • [DYNAMIC_EXECUTION]: The skill authorizes the creation and execution of 'disposable local spikes' to verify code behavior. While this involves runtime code generation and execution, the instructions scope these actions to local verification only and require explicit user authorization for the implementation phase.
  • [COMMAND_EXECUTION]: The package includes Python scripts (scripts/validate.py and scripts/test_skill.py) for validating the skill's structure and evaluation schemas. Additionally, it directs the agent to use standard framework tools (e.g., composer, npm, vitest) for local testing and assessment. All identified command patterns are standard for development workflows and include internal checks to prevent file system escape.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill contains a dedicated reference file (references/production-data.md) that establishes strict safety protocols for data access. It mandates read-only inspection, requires the use of aggregate or redacted data, and explicitly instructs the agent never to request or store credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 12:39 AM
Security Audit — agent-trust-hub — idiomatic