scalekit-code-doctor

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill incorporates robust security guardrails, explicitly instructing the agent to verify all API methods, parameters, and imports against bundled reference files and official documentation before providing them to the user. Code examples correctly utilize environment variables for secret management and secure cookie configurations.
  • [EXTERNAL_DOWNLOADS]: The skill references external resources including docs.scalekit.com and GitHub repositories under the scalekit-inc and scalekit-developers organizations. These are recognized as authoritative vendor-controlled domains for API documentation and code examples.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests user-provided code snippets for review (SKILL.md, Step 4). While explicit boundary markers for user data are absent, the risk is mitigated by instructions to cross-reference every call against local reference files (references/REFERENCE.md) and to flag any unverified methods. Capability inventory includes local file access and network-based documentation lookup.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 09:53 AM
Security Audit — agent-trust-hub — scalekit-code-doctor