circleci
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill contains explicit prompt injection patterns (e.g., 'ignore previous instructions') within its evaluation test suite (
references/evals.yaml). These are used for benchmarking the agent's resistance to adversarial attacks and are documented as expected strings inreferences/prompt-injection-expected-context.json. - [EXTERNAL_DOWNLOADS]: The skill references the
ctx7CLI tool, which can be run vianpxor installed vianpm. This is the primary interface for the Context7 platform used to manage these skills and refresh documentation. - [COMMAND_EXECUTION]: The instructions in
SKILL.mdinclude shell command sequences for searching skills, generating guidance, and validating CircleCI configurations using thectx7andcircleciCLI tools. - [DATA_EXPOSURE]: The skill mentions the location of local environment variables (
~/.codex/.env) used for crawl jobs. This is used for internal configuration context and does not involve instructions for exfiltration.
Audit Metadata