ai-product
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: This skill serves as an educational and instructional toolkit for building AI-powered products, covering patterns for reliability, cost optimization, and user experience.
- [PROMPT_INJECTION]: Static analysis identified potential injection patterns in
references/sharp_edges.md. However, these are false positives; the strings (e.g., 'Ignore all previous instructions') are used as illustrative examples within a security guide to teach developers how to identify and prevent attacks, rather than being part of a malicious instruction set. - [CREDENTIALS_UNSAFE]: The file
references/validations.mdcontains regular expressions intended to detect hardcoded API keys in source code (e.g., patterns for OpenAI and Anthropic keys). These are diagnostic patterns for a linter and do not include any actual hardcoded secrets. - [NO_CODE]: The skill consists entirely of markdown documentation and reference materials. While it contains numerous code snippets (TypeScript and Python) demonstrating best practices, none of these are executed by the skill itself.
Audit Metadata