craft

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for software development assistance, providing detailed instructions for improving accessibility (ARIA, semantics), analytics implementation, and performance (N+1 queries, virtualization).
  • [COMMAND_EXECUTION]: The skill suggests the use of standard search utilities such as grep, awk, and wc to identify code patterns and measure project baselines. These commands are intended to be executed locally on the user's source code and do not perform network operations or access sensitive system files.
  • [DATA_EXPOSURE]: The skill reads project-specific configuration files (e.g., .dev-agent/config.yaml, .telemetry/tracking-plan.yaml) and source code to tailor its advice. This access is necessary for its stated purpose and does not involve harvesting credentials or personal data.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external source code provided by the user, which represents a data ingestion surface. However, it implements structural boundaries through specific analysis modes and lacks high-risk capabilities that could be exploited via malicious content embedded within the analyzed code. (Severity: LOW).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 03:04 PM
Security Audit — agent-trust-hub — craft