skills/spences10/skills/research/Gen Agent Trust Hub

research

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses WebFetch and tavily_extract_process to retrieve documentation from well-known sources such as npmjs.org, unpkg.com, and github.com. It retrieves content from the community tool npmx.dev for type documentation, which is used for data retrieval only.
  • [SAFE]: Bash commands for git clone and gh api are correctly scoped to /tmp/ directories and focused on information retrieval and cleanup, adhering to best practices for agent-based research tasks.
  • [SAFE]: The skill implements advanced verification patterns, including Chain-of-Verification (CoVe) and atomic fact decomposition, which effectively manage the risks associated with processing external untrusted data (Indirect Prompt Injection surface).
  • [SAFE]: No obfuscation, data exfiltration, persistence mechanisms, or unauthorized privilege escalation attempts were detected in the instructions or reference files.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 09:59 PM