mcaf-source-control
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses structured instructional language for policy generation. No attempts to override safety guidelines or bypass agent constraints were identified.
- [DATA_EXFILTRATION]: No network operations, credential harvesting, or unauthorized data transmission patterns were found. The skill focuses on documentation and policy enforcement.
- [REMOTE_CODE_EXECUTION]: The skill does not download or execute external scripts or packages. No dynamic execution patterns are present.
- [COMMAND_EXECUTION]: No shell commands or system process invocations are used within the skill instructions or references.
- [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or private tokens were detected. The skill specifically includes guidance on rotating and cleaning secrets accidentally committed to git history.
- [NO_CODE]: The skill consists entirely of markdown documentation and guidance references without any executable scripts or configuration files.
Audit Metadata