render-env-vars

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized access attempts were identified. The skill contains legitimate instructional content for platform configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a potential surface for indirect prompt injection as it facilitates the configuration of environment variables and secrets, though no executable risk is identified.
  • Ingestion points: User-provided environment variable values, secret file content, and environment group definitions mentioned in SKILL.md and references/wiring-reference.md.
  • Boundary markers: The instructions do not specify delimiters or markers to isolate environment variable values from the agent's instructions.
  • Capability inventory: No executable scripts, subprocess calls, or network operations are included in the skill files.
  • Sanitization: The skill does not provide instructions for the agent to sanitize or validate the content of the environment variables it processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 11:04 AM
Security Audit — agent-trust-hub — render-env-vars