developer-case-study

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external data sources such as interview transcripts, support tickets, and GitHub pull requests.
  • Ingestion points: Data is ingested via workflow steps in SKILL.md and interview guides in references/source-interview-guide.md.
  • Boundary markers: The instructions do not mandate specific technical delimiters for untrusted data, but they require a human-in-the-loop approval process.
  • Capability inventory: No code execution, file writing, or network operations are present in the skill.
  • Sanitization: The skill includes a 'Publication gate' that requires human review of technical accuracy and a specific 'Approval track' for redacting sensitive information.
  • [SAFE]: The skill contains no executable code, package dependencies, or shell commands. It functions strictly as a high-level instruction set for the AI agent.
  • [SAFE]: The skill references established industry resources and case studies from well-known technology organizations (e.g., Temporal, Honeycomb, PostHog, Vercel) to provide templates and examples.
  • [SAFE]: Proactive security instructions are provided in references/approval-and-anonymization.md, directing the agent to redact sensitive information like cluster sizes, internal service codenames, and ticket IDs to prevent accidental data exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:14 PM
Security Audit — agent-trust-hub — developer-case-study