audit-context-building

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary purpose is to establish a rigorous methodology for code comprehension, which is a standard task in security research.
  • [PROMPT_INJECTION]: Instructions such as "This skill governs how Gemini thinks" and the "Rationalizations" table are used to define a structured analytical approach rather than overriding safety protocols or bypassing AI constraints.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials, API keys, or sensitive file paths (e.g., .ssh, .aws) are present in the skill files or scripts. The DEX analysis example uses generic smart contract variables like msg.sender.
  • [REMOTE_CODE_EXECUTION]: The skill does not contain any commands for downloading external scripts or executing remote code (e.g., curl | bash). The installation command mentioned in the documentation refers to a plugin management system and targets a trusted organization.
  • [COMMAND_EXECUTION]: The provided evaluation script (scripts/evaluate.py) is a benign skeleton that only prints status messages and performs basic directory name resolution.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 02:08 PM
Security Audit — agent-trust-hub — audit-context-building