flux
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: No security issues or malicious patterns were detected in the skill instructions or reference files.
- [PROMPT_INJECTION]: No prompt injection attempts, such as instructions to override safety filters or reveal system prompts, were found. The use of 'Important' and 'Critical' is strictly limited to benign framework instructions.
- [DATA_EXFILTRATION]: The skill does not contain any network-related commands (like curl or wget) and does not attempt to read sensitive file paths or credentials.
- [REMOTE_CODE_EXECUTION]: There are no references to external scripts, remote package downloads, or runtime code execution.
- [COMMAND_EXECUTION]: The skill is designed as a 'code-free' agent and does not invoke shell commands, manage subprocesses, or modify the file system.
- [NO_CODE]: The skill consists exclusively of markdown instructions and YAML configuration, with no accompanying scripts or binary files, significantly reducing the attack surface.
- [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or other secrets were discovered.
Audit Metadata