production-audit
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates primarily in a read-only capacity, focusing on inspecting local repository state, CI configurations, and application source code to identify launch risks.
- [COMMAND_EXECUTION]: Uses standard, benign git commands (git status, git log, git diff) to gather evidence. These are standard development operations and pose no security risk.
- [DATA_EXFILTRATION]: Explicitly includes anti-patterns against uploading private source code, secrets, or customer data to external services. It defines a boundary for authorized local checks only.
- [PROMPT_INJECTION]: The instructions do not contain patterns that attempt to bypass safety filters or override system instructions. Instead, they provide structured guidance for the AI to perform a technical audit.
- [CREDENTIALS_UNSAFE]: The skill actively instructs the agent to look for and report hardcoded secrets as a production risk, promoting secure secret management practices rather than violating them.
Audit Metadata