anti-over-engineering

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill consists entirely of instructional markdown, licensing, and evaluation configuration. No executable code, binary files, or hidden scripts were identified in the distribution files.\n- [PROMPT_INJECTION]: The instructions utilize persona-based role-play (e.g., 'You are a Staff engineer') and strict directives to enforce restraint and simplicity. These behavioral guidelines are task-focused and do not attempt to bypass safety filters or override system-level constraints.\n- [INDIRECT_PROMPT_INJECTION]: The skill establishes a logic for 'Over-Engineering Detection' that monitors user feedback for specific triggers (e.g., 'too much', 'revert'). Ingestion points: User-supplied feedback and agent diff output monitored in SKILL.md and evals/evals.json. Boundary markers: None explicitly defined. Capability inventory: The skill does not define or request new file-write, shell execution, or network capabilities. Sanitization: None. While this creates a data ingestion surface, the resulting actions are defensive (stopping or reverting changes) and intended to limit the agent's impact.\n- [EXTERNAL_DOWNLOADS]: Reference documentation in compatibility.md describes installation via a GitHub repository associated with the skill author (JPeetz/agent-skills). This follows standard package management and deployment patterns for the targeted platforms.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — anti-over-engineering