programming-principles
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of text-based guidelines and instructions derived from established software engineering books. It does not include any executable code or external scripts.
- [SAFE]: No evidence of prompt injection or malicious overrides was found. The use of strong directives like 'OBEY' is consistent with the skill's purpose of providing rigorous coding standards for the agent to follow.
- [SAFE]: The skill does not contain hardcoded credentials, sensitive file paths, or suspicious network operations. It uses standard developer tools (git, gh CLI) in a descriptive manner for workflow documentation.
- [SAFE]: The 'code-assessment-workflow.md' defines a structured process for evaluating repositories. While this involves reading untrusted code (which is an inherent risk for any review tool), the skill itself does not provide sinks for code execution or exfiltration based on that data.
- [SAFE]: Metadata and source references (e.g., to Matt Pocock's repository) are transparent and point to well-known community resources.
Audit Metadata