auditing

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains definitions for detecting prompt injection (e.g., phrases like 'ignore previous instructions' or 'override safety') within its security checklists. These are parameters used by the auditor agent to evaluate target plugins and do not constitute an attempt to override the primary agent's instructions.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the analysis of external repositories by cloning from GitHub. This functionality is restricted to shallow-cloning into a specific workspace directory (.bundles-forge/repos/) and is governed by a policy that explicitly forbids the execution of hooks or scripts during the download phase.
  • [COMMAND_EXECUTION]: The skill utilizes a suite of internal Python scripts and the bundles-forge CLI to generate diagnostic baselines. These operations are scoped to the project environment and do not involve arbitrary shell execution or privilege escalation.
  • [DATA_EXFILTRATION]: No exfiltration patterns were detected. The skill's primary function includes a security scanner (audit_security.py) designed to identify and report exfiltration attempts in audited code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 08:39 PM
Security Audit — agent-trust-hub — auditing