audit-schema
Pass
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill's primary function is local static analysis of project files. It uses platform-provided tools (Read, Glob, and Grep) to identify schema definitions and evaluate them against best practices.\n- [DATA_EXPOSURE]: The skill inspects schema definitions and entity models. This data remains within the local environment as the skill does not use network tools or external communication channels.\n- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection through the files it processes. Ingestion points: YAML/JSON spec files, C# entity models, and migration files (SKILL.md). Boundary markers: Absent. Capability inventory: Read, Glob, Grep, Task, Skill (SKILL.md). Sanitization: Absent. While the attack surface exists, the risk is mitigated as the skill does not have permissions for command execution or remote connections.
Audit Metadata