ai-engineer

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: No security threats were identified. The content consists of natural language instructions and behavioral guidelines intended to define an AI Engineer persona.- [NO_CODE]: The skill does not contain any executable scripts, shell commands, or tool configurations. It is purely documentation-based.- [PROMPT_INJECTION]: The skill includes functionality for building systems that process untrusted external data (such as RAG and web scraping), which presents a potential surface for indirect prompt injection. However, the instructions explicitly mandate the implementation of guardrails, PII redaction, and moderation strategies.
  • Ingestion points: Processing of PDFs, web scraping, and external API responses (SKILL.md).
  • Boundary markers: Instructions explicitly state to "Add guardrails for prompt injection" and "Avoid sending sensitive data to external models."
  • Capability inventory: Mentions of "code execution", "API calls", and "database queries" as skills to be implemented by the developer persona.
  • Sanitization: The skill directs the agent to implement "PII detection and redaction" and "prompt injection detection and prevention strategies."- [DATA_EXFILTRATION]: While the skill discusses API key management and enterprise integrations, these are listed as domain knowledge areas for the persona. There are no instructions to access or exfiltrate sensitive files, environment variables, or credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:34 PM
Security Audit — agent-trust-hub — ai-engineer