scope-check
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of Markdown instructions and documentation. There are no scripts, binaries, or automated network commands included in the package.
- [SAFE]: External references (GitHub, attribution links) point to known development resources and are documented for transparency and licensing compliance. No automated downloads or remote code execution patterns were identified.
- [SAFE]: The 'Prompt Injection' category was evaluated due to the presence of instruction-override language (e.g., 'User overrides', 'HARD-GATE'). However, these are legitimate control flow mechanisms designed to let the user guide the agent's workflow rather than bypass safety filters or exfiltrate data.
- [SAFE]: The skill uses a structured 'Assumption Ledger' which promotes security best practices by requiring the agent to verify repository facts before proceeding with implementations.
Audit Metadata