skills/ooiyeefei/ccc/mvp-launch/Gen Agent Trust Hub

mvp-launch

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely informational and diagnostic. It provides a structured 10-point checklist for MVP readiness and a series of grep/glob patterns to help developers audit their own codebases for standard implementation patterns.
  • [COMMAND_EXECUTION]: The skill provides search patterns and commands for the Stripe CLI. These are intended to be executed by the developer manually to verify their own application state and are not executed by the agent automatically.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill discusses sensitive configuration such as Stripe API keys and webhook secrets. However, it correctly advises developers to manage these via environment variables and does not include any hardcoded credentials or instructions that would exfiltrate data to an untrusted source.
  • [PROMPT_INJECTION]: No prompt injection patterns were found. The 'IMPORTANT' sections in the documentation are standard instructional highlights and do not attempt to bypass safety filters or override agent constraints.
  • [INDIRECT_PROMPT_INJECTION]: While the skill involves the agent searching through a user's codebase (untrusted data ingestion), it does so using specific, developer-provided search patterns. It lacks exploitable capabilities like automated remote execution or file writing that would represent a high-risk attack surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 11:45 AM
Security Audit — agent-trust-hub — mvp-launch