context-engineering

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of instructional text and templates for project rules files (e.g., CLAUDE.md). It does not contain executable code, scripts, or malicious commands.
  • [DATA_EXPOSURE]: The skill explicitly includes security guidelines for agents, such as 'Never commit .env files or secrets' and 'Ask before modifying database schema'.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides defensive strategies by instructing the agent to treat 'User-submitted content' or 'external documentation' as untrusted data rather than directives to follow.
  • [COMMAND_EXECUTION]: While the skill mentions development commands (e.g., npm test, npm run lint), these are provided within static documentation templates as examples for project configuration and are not executed by the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 08:32 AM
Security Audit — agent-trust-hub — context-engineering