putio-frontend-dev

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [SAFE]: Analysis of the skill instructions and references shows they focus exclusively on legitimate frontend engineering tasks and security best practices. No malicious code or prompt injection patterns were found.\n- [EXTERNAL_DOWNLOADS]: The skill facilitates the setup of a development environment by downloading trusted tools (e.g., GitHub CLI, SOPS) and the vendor's own CLI (putio-cli) from official sources like GitHub. These operations are consistent with the skill's purpose and follow established engineering practices.\n- [INDIRECT_PROMPT_INJECTION]: The skill includes explicit defensive instructions to treat strings resolved from external contracts as data and never as instructions, demonstrating clear awareness of and protection against indirect prompt injection.\n- [CREDENTIALS_UNSAFE]: The skill incorporates robust guidance on secret management, advocating for the use of SOPS and age for encryption and strictly forbidding the commit of plaintext secrets, tokens, or private keys to repositories. It establishes clear boundaries to prevent credential leakage in logs, state dumps, and transcripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 01:55 PM
Security Audit — agent-trust-hub — putio-frontend-dev