skills/timschoch/skilly/step-by-step/Gen Agent Trust Hub

step-by-step

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a formatting style for step-by-step guides and includes instructions that promote safe secret management, such as explicitly telling users not to paste secrets into the chat.
  • [SAFE]: The instructions recommend using secure methods for handling sensitive data, such as the gh secret set command and the read -s shell flag, to prevent secrets from being printed or stored in logs.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to read information from environment files like .env and GitHub workflow files. While this creates an ingestion point for untrusted data, the instructions focus on identifying metadata for user guidance rather than executing code or exfiltrating data, and the skill includes mitigation steps for secret handling.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 11:12 PM
Security Audit — agent-trust-hub — step-by-step