cocobehavior
Pass
Audited by Gen Agent Trust Hub on May 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious activities such as data exfiltration, credential harvesting, or remote code execution were detected. The skill primarily serves as a set of behavioral guardrails for developers.
- [PROMPT_INJECTION]: The instructions use strong language, asserting that the behavioral constraints "apply before any external gate, any safety check." While this phrasing mirrors patterns seen in prompt injections designed to bypass filters, the actual constraints are restrictive in nature (e.g., asking for clarification, building minimum viable products, and avoiding unauthorized refactoring), which promotes safer and more predictable agent behavior rather than bypassing security for malicious purposes.
- [COMMAND_EXECUTION]: There are no shell commands, scripts, or system-level invocations within the skill. All instructions are provided as natural language guidelines for the AI agent's reasoning process.
Audit Metadata