devrel-analytics
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely instructional, providing a framework for designing tracking plans, event taxonomies, and funnel views. It does not contain any executable scripts, shell commands, or network-active components.- [CREDENTIALS_SAFE]: No hardcoded credentials, API keys, or sensitive file paths (e.g., .ssh, .aws) are present. The skill explicitly mandates excluding PII and PII-shaped identifiers from all tracking properties in its instructions and templates.- [REMOTE_CODE_EXECUTION]: No remote code execution patterns, such as
curl | bashor dynamic script loading, were detected. References to external services like Plausible, GitHub, npm, and PyPI are strictly for documentation and data-counting methodology.- [PROMPT_INJECTION]: The instructions focus on defining the agent's role as a measurement engineer. No patterns attempting to bypass safety filters, override system instructions, or extract system prompts were found.- [INDIRECT_PROMPT_INJECTION]: Although the skill defines an "Interview" workflow to gather user requirements, it lacks the necessary capabilities (such as file writing, shell access, or external API calls) that would enable a prompt injection attack via user input. The output is restricted to a markdown document based on a static template.- [OBFUSCATION]: The skill content is clear and uses standard markdown and JSON. No base64, zero-width characters, homoglyphs, or other obfuscation techniques were identified.
Audit Metadata