deprecation-and-migration

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill is comprised entirely of Markdown files providing engineering guidance, checklists, and orchestration patterns. It contains no scripts (.sh, .py, .js), executables, or platform-specific configuration that would trigger automated actions.
  • [EXTERNAL_DOWNLOADS]: The documentation references several well-known developer tools (e.g., npx axe-core, npx lighthouse, npx pa11y) and libraries (e.g., web-vitals). These are documented as standard practices for the user to implement in their own projects and do not involve the skill itself downloading or executing remote content.
  • [PROMPT_INJECTION]: The SKILL.md file contains instructional content for an AI agent to help it plan system migrations. There are no attempts to override safety filters, bypass system instructions, or extract sensitive internal prompts.
  • [DATA_EXFILTRATION]: No network operations or sensitive file access patterns are present. The security-checklist.md specifically advises against logging secrets and PII, promoting secure practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:54 AM
Security Audit — agent-trust-hub — deprecation-and-migration