audit-doctrine

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely descriptive and instructional, containing no executable code, remote script downloads, or network operations.
  • [PROMPT_INJECTION]: The instructions do not contain markers intended to bypass safety filters or override system behavior. Terms like 'CRITICAL' or 'Phase' are used within a project management and auditing context, not for jailbreaking.
  • [DATA_EXFILTRATION]: There are no patterns suggesting the reading of sensitive files or the transmission of data to external domains. The scope is limited to project-internal 'lint' and 'ratchet' documentation.
  • [COMMAND_EXECUTION]: The skill does not invoke shell commands, subprocesses, or use any platform-specific command execution syntax.
  • [REMOTE_CODE_EXECUTION]: No external dependencies (npm, pip) or remote script fetching (curl, wget) are present.
  • [INDIRECT_PROMPT_INJECTION]: While the skill analyzes 'custom rules' and 'governance docs', it specifies a read-only audit workflow and encourages human-in-the-loop reasoning ('worked example', 'self-critique'), minimizing risks associated with processing untrusted data.
  • [OBFUSCATION]: No encoded strings, homoglyphs, or zero-width characters were detected in the content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 05:55 AM
Security Audit — agent-trust-hub — audit-doctrine