ccf-common

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill provides strong defensive instructions against indirect prompt injection. Specifically, references/privacy-and-evidence.md explicitly commands the agent to ignore instructions embedded within manuscripts, reviews, and other external source materials.
  • [DATA_EXFILTRATION]: No exfiltration patterns were detected. The skill includes a dedicated privacy script (scripts/check_path_privacy.py) designed to detect and prevent accidental leaks of personal information or absolute paths in the repository.
  • [COMMAND_EXECUTION]: The repository contains maintenance scripts (e.g., check_sources.py, check_v04.py). These scripts perform read-only validation of the repository state and source registries. They are designed for developer use and do not process untrusted user input for code execution.
  • [EXTERNAL_DOWNLOADS]: The source registry (references/source-registry.yaml) contains a comprehensive list of academic and technical URLs. These references target reputable research platforms (e.g., NeurIPS, ICLR, ACM, IEEE, arXiv) and official developer resources, which are consistent with the skill's purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 08:26 AM
Security Audit — agent-trust-hub — ccf-common