determinism-audit
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is composed strictly of markdown documentation and instructional guidelines. It does not include any executable scripts, binaries, or automated configuration files.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a process for analyzing external project data and build scripts, which represents a potential surface for indirect prompt injection if the project being audited is malicious. However, this risk is inherent to the intended use of a development auditing tool and does not indicate a flaw in the skill itself.
- Ingestion points: External project source code, build configurations, and test commands identified in SKILL.md.
- Boundary markers: None specified in the instructions.
- Capability inventory: Relies on the agent's external tools for shell execution and file modification.
- Sanitization: None provided within the instructions.
Audit Metadata