devrel-metrics

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional and strategic, containing no executable scripts, shell commands, or network-active components. All content is focused on methodology and strategic decision-making.
  • [SAFE]: External references to community standards, such as the CHAOSS project and the Developer Relations Foundation, are legitimate and used appropriately for documentation and defining industry terminology.
  • [SAFE]: The skill references other skills within the author's ecosystem (e.g., samber/developer-relations-skills@devrel-analytics). These are identified as vendor-owned resources used for modular functionality and scoping.
  • [SAFE]: While the skill defines an interview process that ingests user-provided information to generate a measurement plan, it lacks dangerous capabilities (such as file system writes, network requests, or dynamic code execution) that would make it vulnerable to indirect prompt injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:14 PM
Security Audit — agent-trust-hub — devrel-metrics