agentation

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses a Python diagnostic script (scripts/check_watch_mode_readiness.py) to verify local project configuration. This script is restricted to reading local file metadata (such as package.json and React entry points) and does not perform network requests or execute remote code.- [SAFE]: The skill includes strong security guardrails in references/contract.yaml and SKILL.md, mandating the redaction of secrets/tokens and requiring explicit human confirmation before expanding the scope of automated edits.- [SAFE]: Documentation references for external sites (agentation.com, benji.org) and installation paths (npx skills add...) are transparently disclosed and consistent with the skill's stated purpose of platform integration.- [SAFE]: The skill shows awareness of indirect prompt injection risks by explicitly labeling annotation content as untrusted input and providing evaluation cases to ensure the agent rejects malicious payloads like exfiltration attempts.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 01:13 PM
Security Audit — agent-trust-hub — agentation