python
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill documents command execution via
subprocess.runbut strictly enforces safe practices. It explicitly teaches using list-based arguments instead of shell strings (shell=True) and implements anALLOWED_PROGRAMSwhitelist to prevent arbitrary command execution. The occurrence ofrm -rf /inreferences/threat-model.mdandSKILL.mdis correctly identified as an educational example of what to prevent, rather than a malicious instruction. - [DATA_EXFILTRATION]: The skill promotes secure data handling by instructing the agent to load secrets from environment variables rather than hardcoding them. It also provides robust path containment logic using
pathlib'sis_relative_toto prevent path traversal attacks. - [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing untrusted data (Pydantic models for user creation). However, the instructions focus entirely on strict schema validation, type checking, and regex-based sanitization of that data, which serves as a mitigation for injection attacks.
- [DYNAMIC_EXECUTION]: While the skill mentions
picklein the threat model, it correctly identifies it as a high-risk anti-pattern for untrusted data and provides aRestrictedUnpicklerimplementation as a security example for legacy support scenarios.
Audit Metadata