gleam-package-development

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes standard Gleam CLI tools (gleam new, gleam add, gleam test, gleam hex) for package lifecycle management and authentication.
  • [EXTERNAL_DOWNLOADS]: Instructions include downloading dependencies from the official Hex.pm registry and utilizing well-known GitHub Actions (erlef/setup-beam) for CI/CD workflows.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes project files and documentation during the development and publication workflow.
  • Ingestion points: The agent reads package configuration (gleam.toml), documentation (README.md, CHANGELOG.md), and Gleam source code from the src/ directory.
  • Boundary markers: No specific delimiters or instructions to ignore embedded prompts in processed files are provided.
  • Capability inventory: The skill performs network operations via gleam add (fetching packages) and gleam hex publish (publishing to registry).
  • Sanitization: No explicit sanitization or validation of the ingested project content is described, which is standard for development-oriented tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 05:27 PM
Security Audit — agent-trust-hub — gleam-package-development