publish-guard

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely instructional and functions as a content auditor. It does not require any specialized tools or permissions to execute its primary purpose.
  • [NO_CODE]: There are no scripts (Python, JavaScript, shell) or external dependencies included with the skill. All logic is contained within the Markdown instructions and local reference files.
  • [COMMAND_EXECUTION]: No shell commands or dynamic execution patterns were detected. The skill instructions focus on text pattern matching and reporting.
  • [DATA_EXFILTRATION]: There are no network operations, hardcoded credentials, or patterns suggesting the exfiltration of sensitive data. The skill only processes user-provided text for compliance reporting.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes untrusted user content, the risk is negligible as the skill lacks any capabilities (file writing, network access, tool usage) that could be exploited via injection. It strictly outputs a markdown report based on its internal rules.
  • Ingestion points: User-provided text for compliance scanning in SKILL.md.
  • Boundary markers: None explicitly defined in the prompt instructions.
  • Capability inventory: No tools or risky functions (exec/eval) are used or requested.
  • Sanitization: Not applicable for this skill's text-only reporting functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 01:41 PM
Security Audit — agent-trust-hub — publish-guard