skills/leonardoacosta/skills/improve/Gen Agent Trust Hub

improve

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted repository data, creating a potential surface for indirect prompt injection. However, it implements strong logical mitigations by instructing the agent to report prompt-injection-like content as a finding rather than following it (SKILL.md, Hard Rule 5).
  • Ingestion points: Reads repository files including README, ADRs, and source code (SKILL.md, Phase 1).
  • Boundary markers: Explicitly mandates treating repository content as data, not instructions (SKILL.md, Hard Rule 5).
  • Capability inventory: Limited to read-only analysis and suggestion generation; implementation is delegated to separate workflows (apply, feature).
  • Sanitization: Requires direct confirmation of cited evidence and rejection of speculative findings (SKILL.md, Hard Rule 6).
  • [CREDENTIALS_UNSAFE]: The skill explicitly forbids the reproduction of secret values, requiring that only locations and credential types be cited in findings (SKILL.md, Hard Rule 4). Recommendation of rotation is encouraged if exposure is plausible.
  • [DATA_EXFILTRATION]: No network exfiltration patterns or suspicious external calls were identified. The skill operates primarily on local repository data for auditing purposes and follows a read-only audit policy (SKILL.md, Hard Rule 1).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:41 PM
Security Audit — agent-trust-hub — improve