agent-engineering-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a best-practices framework for agent engineering, focusing on reliability and security. It details the agent loop, memory management, and safe Model Context Protocol (MCP) server usage.
  • [PROMPT_INJECTION]: The skill text contains phrases typically associated with prompt injection, such as "Ignore previous instructions." These are correctly identified as educational examples within a dedicated 'Threat Model' section to help developers understand and defend against indirect prompt injection.
  • [DYNAMIC_EXECUTION]: The skill includes reference implementations for running code within secure, sandboxed Docker containers. These patterns use best practices like dropping capabilities, disabling network egress, and enforcing resource limits (CPU/Memory/PIDs).
  • [DATA_EXFILTRATION]: The instructions provide explicit guidance on preventing data exfiltration through egress allowlists and resolution-based URL validation to block Server-Side Request Forgery (SSRF) and metadata endpoint access.
  • [COMMAND_EXECUTION]: While the skill frontmatter allows the 'Bash' tool, the instructions themselves strongly advise against exposing raw executors (like shell or SQL) to models, recommending instead the use of narrow, parameterized operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:12 AM
Security Audit — agent-trust-hub — agent-engineering-expert