project-vendor-boundary

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill is entirely instructional, providing a mental model and workflow steps for an agent to follow when interacting with third-party code. It does not contain any scripts, shell commands, or automation triggers.
  • [SAFE]: The instructions promote secure and stable development practices, such as inspecting provenance, validating narrow build paths, and treating network-heavy tasks (like fetching submodules) as separate, explicit actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 05:58 PM
Security Audit — agent-trust-hub — project-vendor-boundary