engineering-skills

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions and automated commands for downloading official tools and libraries, such as the @anthropic/gws CLI tool, the ai-agent-skills installer, and various Node.js dependencies for Playwright and MCP integrations from the official npm registry.
  • [COMMAND_EXECUTION]: Multiple Python automation tools (e.g., pr_analyzer.py, gws_doctor.py, workspace_audit.py) use subprocess.run() to interface with standard CLI utilities like git and gws. Additionally, the playwright-pro sub-skill implements automated hooks that execute shell scripts for test validation and environment detection upon file operations.
  • [PROMPT_INJECTION]: The ai-security sub-skill documentation and its ai_threat_scanner.py tool contain lists of prompt injection signatures, such as 'ignore previous instructions' and 'DAN mode'. These are part of a defensive signature database used to detect and score injection risks in AI systems, rather than instructions intended to subvert the agent's behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 11:03 AM
Security Audit — agent-trust-hub — engineering-skills