israeli-citizenship-by-descent

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a Python script (scripts/eligibility_intake.py) intended to help users organize their ancestry information. A manual audit of the code confirms it is a standard utility script using only built-in modules (argparse, json, sys). It does not invoke shell commands, spawn subprocesses, or utilize dynamic execution functions such as eval() or exec().
  • [EXTERNAL_DOWNLOADS]: The instructions and reference files contain numerous URLs for verifying legal claims. All identified domains are official government websites (e.g., gov.pl, gov.il, bva.bund.de, gazzettaufficiale.it) or trusted legal repositories (ris.bka.gv.at). These references are consistent with the skill's primary purpose and do not represent a security threat.
  • [DATA_EXFILTRATION]: There is no evidence of network activity, credential harvesting, or unauthorized file access. The skill does not attempt to read sensitive directories (such as .ssh or .aws) or transmit user data to external servers.
  • [PROMPT_INJECTION]: The instructions in SKILL.md are designed to scope the agent's behavior toward information gathering and triage. While static detectors flagged potential concealment, manual review indicates these instructions are safety-oriented guidelines—such as preventing the agent from giving binding legal advice or inventing processing times—rather than attempts to hide malicious intent or bypass system filters.
  • [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or private secrets were found within the skill's scripts or markdown files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 03:58 PM
Security Audit — agent-trust-hub — israeli-citizenship-by-descent