skill-audit
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: Static analysis flagged instructions like 'ignore previous instructions' and role-play triggers. These strings are contained within a 'What Gets Detected' section as examples of malicious patterns for an auditor to find and do not represent an attempt to override the agent's current instructions.
- [EXTERNAL_DOWNLOADS]: The skill mentions 'curl', 'wget', and 'fetch' as indicators of risk when scanning unknown repositories. The skill itself does not perform any network operations or external downloads.
- [CREDENTIALS_UNSAFE]: Potential sensitive paths such as '
/.env' and '/.ssh/id_rsa' are listed as examples of target files in data exfiltration attacks for the purpose of the security audit. No actual credentials or unauthorized file access occur within this skill. - [NO_CODE]: The skill consists entirely of instructional Markdown text. There are no executable scripts, binaries, or dynamic execution patterns present.
Audit Metadata