gleam-package-development
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes standard Gleam CLI tools (
gleam new,gleam add,gleam test,gleam hex) for package lifecycle management and authentication. - [EXTERNAL_DOWNLOADS]: Instructions include downloading dependencies from the official Hex.pm registry and utilizing well-known GitHub Actions (
erlef/setup-beam) for CI/CD workflows. - [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes project files and documentation during the development and publication workflow.
- Ingestion points: The agent reads package configuration (
gleam.toml), documentation (README.md,CHANGELOG.md), and Gleam source code from thesrc/directory. - Boundary markers: No specific delimiters or instructions to ignore embedded prompts in processed files are provided.
- Capability inventory: The skill performs network operations via
gleam add(fetching packages) andgleam hex publish(publishing to registry). - Sanitization: No explicit sanitization or validation of the ingested project content is described, which is standard for development-oriented tasks.
Audit Metadata