gpg-signing

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains various shell and PowerShell commands for GPG key generation, Git configuration, and agent management. These commands are necessary for the skill's functional purpose and do not represent unauthorized or malicious execution.
  • [EXTERNAL_DOWNLOADS]: The skill references official and well-known sources for software installation, including gpg4win.org, gpgtools.org, and standard OS package managers (apt, dnf, pacman, brew, winget). These are trusted sources for the required cryptographic tools.
  • [DATA_EXFILTRATION]: While the skill provides instructions for exporting GPG keys, it does so for the purpose of backup and platform integration (e.g., GitHub). It includes strong security warnings against storing private keys in unencrypted or public locations, such as Git repositories or cloud storage.
  • [PROMPT_INJECTION]: No patterns of prompt injection, safety bypasses, or instructions to override agent behavior were identified in the analyzed content.
  • [SAFE]: The skill focuses on educational content and technical setup for security-enhancing features like commit signing. It adheres to industry-standard best practices for GPG key security, passphrase caching, and environment configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 06:17 PM
Security Audit — agent-trust-hub — gpg-signing