akowe-spring
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a specialized knowledge base for Spring development best practices and does not contain any executable scripts or tool configurations that could be exploited.
- [PROMPT_INJECTION]: No instructions were found that attempt to bypass safety filters, override system prompts, or induce unauthorized behavior.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill includes explicit rules (
config-secrets-stay-externalandsec-credential-storage-and-redaction) that advise developers against hardcoding secrets or logging tokens. No network exfiltration patterns were detected. - [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: All external URLs point to official project documentation (Spring, Jakarta, Hibernate, Project Reactor) or well-known community repositories in the Java ecosystem. The skill does not perform any remote script downloads or installations.
- [DYNAMIC_CONTEXT_INJECTION]: The skill does not utilize dynamic shell execution syntax (
!command) in its markdown files. - [INDIRECT_PROMPT_INJECTION]: While the skill is designed to analyze user-provided code, it lacks the necessary capabilities (such as network access or file-writing tools) to be used as a vector for automated attacks.
Audit Metadata