soia-dev-agent-md-advisor
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates entirely on local text files provided by the user or within the project directory. It performs diagnostic analysis and provides text-based recommendations.
- [DATA_EXFILTRATION]: No network activity or external data transmission was detected. The skill specifically disclaims the use of external APIs, credentials, or sessions.
- [REMOTE_CODE_EXECUTION]: No patterns of remote script downloading or execution were found. The skill does not execute code, run tests, or modify business logic; it only analyzes markdown/YAML configuration files.
- [CREDENTIALS_UNSAFE]: The skill instructions explicitly state it does not read API keys, tokens, or private environment variables. It focuses solely on project instructional metadata.
- [COMMAND_EXECUTION]: While it suggests commands for AGENTS.md templates, it warns that it does not 'invent' commands and requires verification against project files like package.json or Makefile. It does not invoke these commands itself.
- [PROMPT_INJECTION]: No evidence of jailbreak attempts, safety bypasses, or instructions intended to override agent behavior were found. The 'diagnostic dimensions' are benign design patterns.
Audit Metadata