project-scaffold
Pass
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of legitimate boilerplate code and best practice documentation for software development. All referenced vendor-specific libraries are consistent with the author's identity.- [PROMPT_INJECTION]: No behavioral overrides or bypass instructions were found. Trigger phrases used in the description are appropriate for the skill's purpose.- [DATA_EXFILTRATION]: No patterns associated with unauthorized data reading or exfiltration were detected. The conventions include proactive measures to prevent sensitive data exposure.- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect injection surface through user-provided feature names. Ingestion Point: User-supplied domain names interpolated into file templates in SKILL.md. Boundary Markers: Absent; the skill relies on the agent's logic for variable substitution. Capability Inventory: File creation and scaffolding. Sanitization: Not explicitly specified in the instructions for the feature name variable.
Audit Metadata