context-kit

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to clone the JDDavenport/context-kit repository from GitHub.
  • [REMOTE_CODE_EXECUTION]: Mentions the use of installation scripts (scripts/install.sh) from the external repository but includes explicit safety rules requiring the user to inspect these scripts before execution.
  • [DATA_EXFILTRATION]: Provides guidance on handling sensitive personal information, including identity details and work history, with specific safety rules to prevent storing secrets or uploading files to third-party services.
  • [PROMPT_INJECTION]: The skill processes external Markdown templates which could serve as a vector for indirect prompt injection, though it mitigates this by instructing the user to create minimal starter sets and manually review files before use.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 04:04 PM
Security Audit — agent-trust-hub — context-kit