codebase-design

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructional content and architectural glossary terms for software design. No patterns involving system prompt extraction, safety filter bypasses, or 'DAN-style' overrides were identified.
  • [DATA_EXFILTRATION]: No sensitive file paths (e.g., .ssh, .aws), hardcoded credentials, or network operations (curl, wget, fetch) were found in the skill instructions or metadata.
  • [REMOTE_CODE_EXECUTION]: The skill does not contain any commands for package installation (npm, pip) or remote script execution (piping URLs to bash).
  • [OBFUSCATION]: All analyzed files contain plain-text markdown and YAML. No Base64 encoded payloads, zero-width characters, homoglyphs, or hidden URLs were detected.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill does not use shell-execution placeholders or dynamic command injection syntax within the markdown body.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 11:35 AM
Security Audit — agent-trust-hub — codebase-design