zephyr-safety-evidence
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to create and execute local Bash and Python scripts for debugging and scaffolding purposes during the audit process, stored within the
.zephyr-skills/directory.- [SAFE]: The skill provides comprehensive safety guardrails inreferences/safety-guardrails.mdthat explicitly require human review for certification and risk acceptance decisions, mitigating risks associated with autonomous safety claims.- [SAFE]: The workflow includes workspace management instructions using standard Git commands to properly exclude agent-only audit records from being committed to the source repository.- [SAFE]: The skill processes external safety requirements and claims, establishing a potential indirect prompt injection surface; however, the provided instructions include explicit claim boundaries and require fact-based evidence linking to mitigate this risk.
Audit Metadata