skill-audit

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: Static analysis flagged instructions like 'ignore previous instructions' and role-play triggers. These strings are contained within a 'What Gets Detected' section as examples of malicious patterns for an auditor to find and do not represent an attempt to override the agent's current instructions.
  • [EXTERNAL_DOWNLOADS]: The skill mentions 'curl', 'wget', and 'fetch' as indicators of risk when scanning unknown repositories. The skill itself does not perform any network operations or external downloads.
  • [CREDENTIALS_UNSAFE]: Potential sensitive paths such as '/.env' and '/.ssh/id_rsa' are listed as examples of target files in data exfiltration attacks for the purpose of the security audit. No actual credentials or unauthorized file access occur within this skill.
  • [NO_CODE]: The skill consists entirely of instructional Markdown text. There are no executable scripts, binaries, or dynamic execution patterns present.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 06:58 AM
Security Audit — agent-trust-hub — skill-audit