search-first

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides benign instructional content focused on a research-driven development workflow. No evidence of prompt injection, data exfiltration, or obfuscation was found.
  • [EXTERNAL_DOWNLOADS]: The documentation references standard, well-known software packages from established registries (npm, PyPI) such as eslint, httpx, and zod. These are presented as examples of existing solutions to avoid redundant coding.
  • [COMMAND_EXECUTION]: The workflow suggests using common development tools like rg (ripgrep) to inspect the local repository for existing implementations, which is a legitimate and expected task in a coding environment.
  • [DATA_EXFILTRATION]: Instructions to check ~/.claude/settings.json and ~/.claude/skills/ are intended for the agent to determine its own available capabilities and configuration. There are no associated network operations to transmit this information externally.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 10:28 AM
Security Audit — agent-trust-hub — search-first