using-contract-engineering

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as an educational and structural framework for software architects, providing detailed markdown guides and Python snippets that illustrate robust system design principles.
  • [PROMPT_INJECTION]: All instructions and metadata were analyzed; no attempts to bypass agent guardrails, extract system prompts, or inject malicious instructions were found.
  • [DATA_EXFILTRATION]: No network calls, credential harvesting, or access to sensitive file paths (such as .env or SSH keys) are present in the skill.
  • [REMOTE_CODE_EXECUTION]: The skill does not include any mechanism for downloading or executing remote code. The provided code examples are for pedagogical use and do not involve unsafe dynamic execution patterns.
  • [COMMAND_EXECUTION]: There is no usage of the dynamic context injection syntax (!command) or any instructions for the agent to execute dangerous shell commands on the host system.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 08:34 PM
Security Audit — agent-trust-hub — using-contract-engineering