akowe-spring

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a specialized knowledge base for Spring development best practices and does not contain any executable scripts or tool configurations that could be exploited.
  • [PROMPT_INJECTION]: No instructions were found that attempt to bypass safety filters, override system prompts, or induce unauthorized behavior.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill includes explicit rules (config-secrets-stay-external and sec-credential-storage-and-redaction) that advise developers against hardcoding secrets or logging tokens. No network exfiltration patterns were detected.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: All external URLs point to official project documentation (Spring, Jakarta, Hibernate, Project Reactor) or well-known community repositories in the Java ecosystem. The skill does not perform any remote script downloads or installations.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill does not utilize dynamic shell execution syntax (!command) in its markdown files.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is designed to analyze user-provided code, it lacks the necessary capabilities (such as network access or file-writing tools) to be used as a vector for automated attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:12 PM
Security Audit — agent-trust-hub — akowe-spring