ce-reliability-review
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements security best practices by instructing the agent to redact secrets, credentials, and sensitive data by default within the constraints section of SKILL.md.
- [SAFE]: The 'Working Agreement' explicitly warns the agent to treat external inputs such as PR text, commit messages, and documentation as untrusted and forbids the execution of embedded instructions, effectively mitigating indirect prompt injection risks.
- [SAFE]: The prompt injection pattern detected in
references/evals.yamlis a standard evaluation test case used to verify the model's robustness against adversarial inputs (pressure testing) and does not represent a vulnerability in the skill itself. - [SAFE]: Analysis of the workflow and reference files reveals no unauthorized network operations, remote code execution, persistence mechanisms, or data exfiltration patterns.
- [SAFE]: The skill is scoped to its intended purpose of reliability engineering and does not request unnecessary permissions or tools.
Audit Metadata