zephyr-safety-evidence

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to create and execute local Bash and Python scripts for debugging and scaffolding purposes during the audit process, stored within the .zephyr-skills/ directory.- [SAFE]: The skill provides comprehensive safety guardrails in references/safety-guardrails.md that explicitly require human review for certification and risk acceptance decisions, mitigating risks associated with autonomous safety claims.- [SAFE]: The workflow includes workspace management instructions using standard Git commands to properly exclude agent-only audit records from being committed to the source repository.- [SAFE]: The skill processes external safety requirements and claims, establishing a potential indirect prompt injection surface; however, the provided instructions include explicit claim boundaries and require fact-based evidence linking to mitigate this risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 07:53 AM
Security Audit — agent-trust-hub — zephyr-safety-evidence