putio-frontend-repos

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured guidance and security guardrails for repository delivery and standardization.
  • [SAFE]: Commands provided for repository inspection (e.g., rg, jq, find) are used appropriately for analysis and do not exhibit malicious behavior.
  • [SAFE]: Secrets management guidance (Category 2) correctly identifies risks of hardcoded credentials and mandates the use of 1Password-backed references and GitHub Environments with protected secrets.
  • [SAFE]: Supply chain security (Category 4) is prioritized through instructions to pin GitHub Actions to full commit SHAs and verify toolchain provenance for binary builds.
  • [SAFE]: Indirect prompt injection risks (Category 8) are addressed by explicit warnings against interpolating untrusted workflow_dispatch inputs directly into shell scripts and providing sanitization patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 08:07 AM