concept-audit-cn
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of documentation and configuration files (Markdown and YAML) designed to guide the agent through a design audit workflow. No executable scripts, binaries, or automated shell commands were found.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data, such as project specifications and source code, which constitutes an ingestion surface. However, the skill is explicitly defined as read-only and does not possess capabilities for file writing or network communication, mitigating the risk of data exfiltration or system modification via indirect injection.
- [EXTERNAL_DOWNLOADS]: The documentation contains references to academic sources (arXiv, MIT, Essence of Software) and GitHub repositories (ontology-of-everything, jlifyio). These are documented as educational sources for the audit methodology and do not involve runtime downloads or code execution.
- [COMMAND_EXECUTION]: While the documentation mentions the trigger '$concept-audit-cn', this is a platform-specific variable for skill invocation and does not facilitate arbitrary shell command execution.
Audit Metadata