soia-dev-task-execute

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional markdown without any executable code, scripts, or external tool invocations.
  • [DATA_EXFILTRATION]: The instructions include specific safety boundaries that prohibit hardcoding or printing credentials, local paths, account information, or private context.
  • [PROMPT_INJECTION]: No patterns of behavior override or safety bypass were detected. The skill actually reinforces safety by requiring explicit confirmation for high-risk operations like remote writes or deletions.
  • [COMMAND_EXECUTION]: The skill outlines a process for verifying tasks via commands but does not contain any predefined or suspicious command sequences.
  • [INDIRECT_PROMPT_INJECTION]: While the skill involves reading workspace files (contribution guides, test conventions), it provides defensive guidelines such as defining task boundaries and performing independent reviews to mitigate risks from untrusted data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 10:40 AM
Security Audit — agent-trust-hub — soia-dev-task-execute