skills/sentimony/skills/scope-check/Gen Agent Trust Hub

scope-check

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of Markdown instructions and documentation. There are no scripts, binaries, or automated network commands included in the package.
  • [SAFE]: External references (GitHub, attribution links) point to known development resources and are documented for transparency and licensing compliance. No automated downloads or remote code execution patterns were identified.
  • [SAFE]: The 'Prompt Injection' category was evaluated due to the presence of instruction-override language (e.g., 'User overrides', 'HARD-GATE'). However, these are legitimate control flow mechanisms designed to let the user guide the agent's workflow rather than bypass safety filters or exfiltrate data.
  • [SAFE]: The skill uses a structured 'Assumption Ledger' which promotes security best practices by requiring the agent to verify repository facts before proceeding with implementations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 09:26 PM
Security Audit — agent-trust-hub — scope-check