Agent Development

Pass

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a developer toolkit containing documentation and templates for agent architecture. It does not perform any network operations or access sensitive data.
  • [COMMAND_EXECUTION]: The file scripts/validate-agent.sh is a utility script provided to check agent file syntax. It uses standard POSIX tools (grep, sed, awk) for local file validation and does not exhibit malicious behavior or privilege escalation attempts.
  • [PROMPT_INJECTION]: The skill provides structured guidance on designing system prompts and triggering conditions. While it uses "You are..." directives, these are part of legitimate agent templates and do not aim to bypass safety filters or override agent behavior maliciously.
  • [DATA_EXPOSURE]: Analysis of all files, including examples like security-analyzer.md, shows no hardcoded secrets or sensitive file paths. The references to security checks are instructions for agents to identify flaws in other codebases as part of a review workflow.
  • [EXTERNAL_DOWNLOADS]: No external URLs or remote code execution patterns were detected in the scripts or documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 3, 2026, 12:22 PM
Security Audit — agent-trust-hub — Agent Development