developer-live-demo-design

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured guidance and templates for live demo reliability without executing dangerous commands or accessing sensitive files. It uses standard role-play instructions to act as a 'demo reliability engineer' and does not attempt to bypass agent safety filters.
  • [COMMAND_EXECUTION]: The skill includes a bash utility (scripts/demo-checkpoints.sh) intended for use by a developer to manage git tags as restore points within a local demo repository. The script utilizes standard git operations (tagging, checking out) and includes safety checks to prevent accidental data loss in uncommitted working trees. These commands are benign and standard for software development workflows.
  • [DATA_EXPOSURE]: The skill actively promotes security best practices through dedicated documentation (references/surface-exposure.md). It explicitly warns against using real customer data, production credentials, or personal profiles during demos, instead recommending synthetic fixtures, dedicated demo profiles, and placeholder environment variables to prevent accidental data leakage.
  • [REMOTE_CODE_EXECUTION]: No patterns for remote code execution or suspicious external downloads were detected. All external references point to reputable sources (e.g., GitHub repositories of known developers, 9to5Mac) and are used for instructional purposes or as citations for methodology.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:14 PM
Security Audit — agent-trust-hub — developer-live-demo-design