reference-engine
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses strong instructional language (such as "NO EXCEPTIONS", "MUST", and "The Prime Directive") to enforce its methodology of referencing existing code before generation. These instructions are benign and intended to guide the agent toward producing high-quality engineering output based on industry standards.
- [DATA_EXFILTRATION]: No commands for data exfiltration or access to sensitive local files (such as SSH keys or environment variables) were found. The skill operates purely at the level of providing knowledge and workflow instructions.
- [REMOTE_CODE_EXECUTION]: The skill does not contain any scripts or patterns that download or execute remote code. It mentions searching for references on GitHub, which is a common developer workflow.
- [EXTERNAL_DOWNLOADS]: References to external sources like GitHub, Stripe, Vercel, and official documentation are used as examples of best practices and gold-standard implementations. These are informative pointers and do not involve automated, untrusted downloads.
- [COMMAND_EXECUTION]: The skill mentions various shell-related activities (like linting, type-checking, and testing) within the context of CI/CD best practices, but it does not define any executable shell commands that would run on a user's machine.
Audit Metadata