skills/simota/agent-skills/port/Gen Agent Trust Hub

port

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions solely as a design and planning agent, specifically prohibiting implementation at the code level. This limitation prevents the execution of untrusted logic derived from the analyzed web apps.
  • [SAFE]: Security is integrated into the design workflow, with mandatory requirements to use platform-native secure storage (Secure Enclave, Keychain, Credential Manager) for secrets rather than legacy or insecure web storage methods like cookies or localStorage.
  • [SAFE]: The skill analyzes external web codebases (package.json, manifest, API clients) which constitute an ingestion surface for untrusted data. However, the risk of indirect prompt injection is mitigated as the agent is restricted to producing markdown-based design specifications and does not perform executable actions based on the surveyed data. Sanitization is achieved by the agent's role-based constraint to act as a design specialist only.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — port