build-in-public

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a consultative guide for the AI agent and contains no executable scripts, shell commands, or network operations.
  • [EXTERNAL_DOWNLOADS]: The skill references supplementary skills within the author's own namespace (samber/developer-relations-skills). These are legitimate vendor resources and do not involve untrusted third-party code execution.
  • [DATA_EXFILTRATION]: The instructions incorporate comprehensive security boundaries, explicitly blocking the disclosure of unpatched vulnerabilities, private customer information, and sensitive financial data. The skill does not attempt to access or exfiltrate local files, credentials, or environment variables.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests user-provided context via an interview, it lacks the system capabilities (such as tool usage or file writing) that would allow malicious input to cause harmful effects.
  • Ingestion points: User responses to the interview questions in SKILL.md.
  • Boundary markers: Predefined Markdown charter template.
  • Capability inventory: No file-writing, network, or command execution capabilities.
  • Sanitization: Natural language generation with no tool execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 10:15 PM
Security Audit — agent-trust-hub — build-in-public