skills/jscraik/agent-skills/circleci/Gen Agent Trust Hub

circleci

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains explicit prompt injection patterns (e.g., 'ignore previous instructions') within its evaluation test suite (references/evals.yaml). These are used for benchmarking the agent's resistance to adversarial attacks and are documented as expected strings in references/prompt-injection-expected-context.json.
  • [EXTERNAL_DOWNLOADS]: The skill references the ctx7 CLI tool, which can be run via npx or installed via npm. This is the primary interface for the Context7 platform used to manage these skills and refresh documentation.
  • [COMMAND_EXECUTION]: The instructions in SKILL.md include shell command sequences for searching skills, generating guidance, and validating CircleCI configurations using the ctx7 and circleci CLI tools.
  • [DATA_EXPOSURE]: The skill mentions the location of local environment variables (~/.codex/.env) used for crawl jobs. This is used for internal configuration context and does not involve instructions for exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 01:14 PM
Security Audit — agent-trust-hub — circleci