skill-change-verification

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely informational and focused on reporting. It contains explicit instructions in prompts/skill-change-verification.md to avoid publishing, committing, or performing external operations.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns or package installations were detected. The skill mentions tools like skill-up validate, but treats them as external commands for which the user provides results.
  • [DATA_EXFILTRATION]: No network operations or sensitive data access patterns were identified. The workflow is restricted to processing information provided within the agent's context to produce a markdown report.
  • [PROMPT_INJECTION]: The instructions are clear and structured, with no attempts to override safety guidelines or bypass constraints. It includes defensive instructions to report "confirmation required" instead of hallucinating command details.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 08:54 AM
Security Audit — agent-trust-hub — skill-change-verification