context-engineering

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFENO_CODEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill is composed exclusively of Markdown documentation and YAML configuration files. It does not contain any scripts, binaries, or automated tasks that could execute on the host system.
  • [EXTERNAL_DOWNLOADS]: The file references/sequence.md contains a URL referencing the author's repository on GitHub (github.com/lidessen/skills.git). This is a standard reference for versioning and does not involve automated network operations or code downloads.
  • [PROMPT_INJECTION]: The skill involves reading project-specific instructions and source files to audit context delivery, which creates an indirect prompt injection surface. However, the skill lacks any tools for code execution, network access, or file modification that could be exploited.
  • Ingestion points: SKILL.md and commands/design.md direct the agent to read authoritative source artifacts.
  • Boundary markers: The skill emphasizes identifying "source authority" and "delivery projections" to prevent confusion.
  • Capability inventory: The skill has no file-writing, network-access, or command-execution tools.
  • Sanitization: No explicit sanitization of project source data is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 06:32 AM
Security Audit — agent-trust-hub — context-engineering