retaining-developers

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill manages organizational context through local markdown files (.agents/em-context.md and .agents/reports/[name].md). This is a functional requirement for providing personalized management advice based on team history.
  • [SAFE]: External links in references/sources.md target the author's newsletter domain (newsletter.manager.dev). These are legitimate references for the skill's methodology and pose no security risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from local files, which technically introduces an ingestion surface for untrusted data if those files are externally sourced. However, the risk is minimal as the skill only generates text-based management advice. 1. Ingestion points: .agents/em-context.md and .agents/reports/[name].md. 2. Boundary markers: Absent. 3. Capability inventory: Internal text generation and local file writing. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:46 AM
Security Audit — agent-trust-hub — retaining-developers