build-product
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected in this skill. The skill contains only instructional content and architectural guidance for developers.
- [PROMPT_INJECTION]: No evidence of prompt injection or instructions to bypass safety guidelines was found.
- [DATA_EXPOSURE_AND_EXFILTRATION]: No sensitive data access, hardcoded credentials, or network exfiltration patterns were identified.
- [OBFUSCATION]: No obfuscated strings, Base64 encoding, or hidden characters were found.
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill does not perform external package installations or execute remote code from unverifiable sources.
- [COMMAND_EXECUTION]: No shell command execution or subprocess spawning was detected.
- [PRIVILEGE_ESCALATION]: No attempts to escalate privileges or modify system configurations were identified.
- [PERSISTENCE_MECHANISMS]: No persistence mechanisms such as cron jobs or shell profile modifications were found.
- [METADATA_POISONING]: Metadata fields are consistent with the skill's purpose and contain no malicious instructions.
- [INDIRECT_PROMPT_INJECTION]: The skill does not process external untrusted data in a way that creates an injection surface.
- [TIME_DELAYED_OR_CONDITIONAL_ATTACKS]: No time-delayed or conditional execution patterns were detected.
- [DYNAMIC_EXECUTION]: No dynamic code generation or runtime compilation was detected.
- [DYNAMIC_CONTEXT_INJECTION]: No use of dynamic context injection markers was found.
Audit Metadata