digital-twin

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of Markdown and YAML documentation. It does not include any scripts, binaries, or automated tools that could perform unauthorized actions.- [REMOTE_CODE_EXECUTION]: No remote code execution patterns or package installations were detected. The README explicitly states that no runtime dependencies or scripts are required.- [CREDENTIALS_UNSAFE]: No hardcoded secrets or credentials were found. Templates use safe placeholders (e.g., <accountable-owner>) and documentation explicitly advises against hardcoding secrets, recommending the use of environment variables and policy-driven secret management instead.- [DATA_EXFILTRATION]: No network operations or data exfiltration vectors are present. External links point to official documentation from trusted organizations such as NIST, ISO, W3C, and well-known cloud providers.- [PROMPT_INJECTION]: The skill instructions do not contain patterns intended to bypass agent safety filters or override system prompts. Instead, it includes defensive guidance, such as warning against copying untrusted Markdown into executable fields and establishing human-in-the-loop authority gates.- [INDIRECT_PROMPT_INJECTION]: While the skill describes workflows for processing external data (event streams, logs), it includes explicit mitigation strategies. The templates and references mandate independent verification, sanitization of external content, and the use of boundary markers to prevent the agent from obeying embedded instructions in processed data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 05:08 PM
Security Audit — agent-trust-hub — digital-twin