putio-frontend-repos
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides structured guidance and security guardrails for repository delivery and standardization.
- [SAFE]: Commands provided for repository inspection (e.g.,
rg,jq,find) are used appropriately for analysis and do not exhibit malicious behavior. - [SAFE]: Secrets management guidance (Category 2) correctly identifies risks of hardcoded credentials and mandates the use of 1Password-backed references and GitHub Environments with protected secrets.
- [SAFE]: Supply chain security (Category 4) is prioritized through instructions to pin GitHub Actions to full commit SHAs and verify toolchain provenance for binary builds.
- [SAFE]: Indirect prompt injection risks (Category 8) are addressed by explicit warnings against interpolating untrusted
workflow_dispatchinputs directly into shell scripts and providing sanitization patterns.
Audit Metadata