skills/klh/skills/klh-settings-audit/Gen Agent Trust Hub

klh-settings-audit

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill is designed for repository auditing and technology stack detection. It operates entirely through local inspection of project files and does not initiate external network connections.
  • [COMMAND_EXECUTION]: The skill uses basic, read-only shell commands such as ls, find, and cat to identify project structures and dependency files (e.g., package.json, pyproject.toml, .mcp.json). These operations are restricted to the local filesystem and do not pose a security risk in this context.
  • [PROMPT_INJECTION]: Analysis of the instructions shows no attempts to bypass safety filters, extract system prompts, or override agent constraints.
  • [DATA_EXFILTRATION]: There are no patterns suggesting unauthorized data harvesting or exfiltration. Mentions of API keys (e.g., LINEAR_API_KEY) are provided as templates for environment variable references in recommended configurations, rather than as hardcoded secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 11:49 AM
Security Audit — agent-trust-hub — klh-settings-audit