audit-schema

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's primary function is local static analysis of project files. It uses platform-provided tools (Read, Glob, and Grep) to identify schema definitions and evaluate them against best practices.\n- [DATA_EXPOSURE]: The skill inspects schema definitions and entity models. This data remains within the local environment as the skill does not use network tools or external communication channels.\n- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection through the files it processes. Ingestion points: YAML/JSON spec files, C# entity models, and migration files (SKILL.md). Boundary markers: Absent. Capability inventory: Read, Glob, Grep, Task, Skill (SKILL.md). Sanitization: Absent. While the attack surface exists, the risk is mitigated as the skill does not have permissions for command execution or remote connections.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 09:18 AM