software-engineering-guidelines

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains purely instructional content aimed at improving software development quality through best practices like TDD and success criteria definition.
  • [COMMAND_EXECUTION]: The workflow sections instruct the agent to execute standard development tools such as test runners, linters, and type checkers. These are expected behaviors for a software engineering skill and do not involve arbitrary command injection from untrusted sources.
  • [DATA_EXFILTRATION]: No network operations, credential access, or sensitive file exfiltration patterns were detected. The recording rule for follow-up items involves writing to a project-local file (AGENTS.md), which is standard behavior for development-oriented agents.
  • [PROMPT_INJECTION]: The skill uses strong instructional language (e.g., "MUST NOT be skipped") to define its operational scope, but these instructions are benign and do not attempt to bypass system safety filters or override the agent's core identity.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 04:47 AM
Security Audit — agent-trust-hub — software-engineering-guidelines